While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.
We have discovered 353,824 live websites that are affected by CVE-2017-3735.
Product | ![]() |
Category | Web Server Extensions |
Vulnerable Domains | 353,824 live websites (52.78% of OpenSSL install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 2 versions ( 5.00% of all versions) |
![]() | 128,326 websites |
![]() | 34,426 websites |
![]() | 23,861 websites |
![]() | 21,162 websites |
![]() | 13,939 websites |
![]() | 10,884 websites |
![]() | 9,721 websites |
![]() | 8,463 websites |
![]() | 7,756 websites |
.com | 128,510 websites |
.de | 24,696 websites |
.nl | 18,029 websites |
.net | 14,017 websites |
.org | 12,802 websites |
.jp | 8,380 websites |
.ru | 7,521 websites |
.it | 6,328 websites |
.cz | 5,055 websites |
.com.br | 5,030 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.*************.se | ![]() | *** | |
****.com | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
****.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
*.******.***.***.br | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
*.*****.***.***.br | ![]() | *,*** | |
****.**.com | ![]() | *,*** |