CVE-2014-0160: Heartbleed
An out-of-bounds read in OpenSSL's TLS and DTLS heartbeat extension. A malformed heartbeat request tricks the server into echoing back up to 64KB of adjacent process memory, which can contain private keys, session tokens, passwords, and other sensitive data, and leaves no trace in server logs.
View the authoritative record on NVD ↗Affected software
- OpenSSL 1.0.1 through 1.0.1f
How it's exploited
Send a heartbeat request that claims a payload length larger than the actual payload sent; OpenSSL copies that many bytes from memory into the reply, leaking whatever adjacent heap memory happens to be there.
Severity
CVE-2014-0160 carries a CVSS 3.1 base score of 7.5, rated High. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2014-0160 is categorized under CWE-125, the general weakness pattern behind this specific vulnerability.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Remediation
Upgrade to OpenSSL 1.0.1g or later, then reissue TLS certificates and rotate any keys, passwords, or session tokens that may have resided in server memory while the vulnerable version was in use.
Frequently asked questions
What is CVE-2014-0160?
An out-of-bounds read in OpenSSL's TLS and DTLS heartbeat extension. A malformed heartbeat request tricks the server into echoing back up to 64KB of adjacent process memory, which can contain private keys, session tokens, passwords, and other sensitive data, and leaves no trace in server logs.
How severe is CVE-2014-0160?
CVE-2014-0160 has a CVSS 3.1 base score of 7.5 out of 10, rated High.
What software is affected by CVE-2014-0160?
CVE-2014-0160 affects OpenSSL 1.0.1 through 1.0.1f.
How do you fix CVE-2014-0160?
Upgrade to OpenSSL 1.0.1g or later, then reissue TLS certificates and rotate any keys, passwords, or session tokens that may have resided in server memory while the vulnerable version was in use.
Where is the authoritative record for CVE-2014-0160?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2014-0160 at https://nvd.nist.gov/vuln/detail/CVE-2014-0160, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest