CVE-2017-3735

While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g.


We have discovered 353,824 live websites that are affected by CVE-2017-3735.

Test my site




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains353,824 live websites (52.78% of OpenSSL install base)
Vulnerable Versions
  • from 1.0.2 through 1.0.2
  • from 1.1 through 1.1
Vulnerable Versions Count2 versions ( 5.00% of all versions)



Details

  • Published - Aug 28, 2017
  • Updated - Sep 16, 2024

CVE-2017-3735 usage by Country

United States128,326 websites



Germany34,426 websites
Netherlands23,861 websites
Japan21,162 websites
Singapore13,939 websites
France10,884 websites
Korea, South9,721 websites
Russia8,463 websites
China7,756 websites

CVE-2017-3735 usage by TLD

.com128,510 websites
.de24,696 websites
.nl18,029 websites
.net14,017 websites
.org12,802 websites
.jp8,380 websites
.ru7,521 websites
.it6,328 websites
.cz5,055 websites
.com.br5,030 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2017-3735

Top websites that are affected by CVE-2017-3735. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.*************.se United States***
****.com United States***
********.*********.com Singapore*,***
****.com United States*,***
********.com United States*,***
*******.com United States*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
****.**.com United States*,***
See full domain list

FAQ

A total of 353,824 websites have been identified as vulnerable to CVE-2017-3735, discovered through global website indexing conducted by WebTechSurvey.
OpenSSL is susceptible to CVE-2017-3735 vulnerability.
OpenSSL versions before, and including, 1.1 are vulnerable to CVE-2017-3735.

References