Top 10 winner
Heartbleed
Heartbleed Bug
A missing bounds check in OpenSSL's TLS heartbeat extension lets any peer ask for more bytes than it supplied and receive up to 64KB of adjacent process memory, repeatable without limit. It leaks private keys, user credentials, session cookies and plaintext traffic, and leaves no trace in server logs.
Record
- Document
- Heartbleed Bug
- Researcher
- Codenomicon Ltd. http://www.codenomicon.com/
- Published by
- heartbleed.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Codenomicon Ltd. http://www.codenomicon.com/, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .