CVE-2014-0160

ENISA EUVD: EUVD-2014-0217 ↗
Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 7 articles Published: 2014-04-07

EPSS Score

Source: FIRST.org · 2026-05-23
94.46%
probability
This CVE has a 94.46% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.1

Source: VulnerabilityLookup (CIRCL)
7.5
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2 (legacy)

5.0
MEDIUM
Access Vector
Network
Access Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
AV:N/AC:L/Au:N/C:P/I:N/A:N

Description

VulnerabilityLookup (CNA)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Affected Products

n/a
n/a

Attack Intelligence

Exploits & PoC

FiloSottile/Heartbleed

A checker (site and tool) for CVE-2014-0160

2391 2021-02-24
musalbas/heartbleed-masstest

Multi-threaded tool for scanning many hosts for CVE-2014-0160.

574 2015-07-02
titanous/heartbleeder

OpenSSL CVE-2014-0160 Heartbleed vulnerability test

452 2014-05-27
Lekensteyn/pacemaker

Heartbleed (CVE-2014-0160) client exploit

329 2016-01-22
sensepost/heartbleed-poc

Test for SSL heartbeat vulnerability (CVE-2014-0160)

168 2014-07-10
einaros/heartbleed-tools

OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner, data miner and RSA key-restore tools.

98 2014-06-18
mpgn/heartbleed-PoC

:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:

85 2021-02-20
isgroup/openmagic

OpenSSL TLS heartbeat read overrun (CVE-2014-0160)

39 2014-04-11
jdauphant/patch-openssl-CVE-2014-0160

Patch openssl #heartbleed with ansible

19 2014-12-02
DisK0nn3cT/MaltegoHeartbleed

Maltego transform to detect the OpenSSL Heartbleed vulnerability (CVE-2014-0160)

18 2014-05-01
OffensivePython/HeartLeak

CVE-2014-0160 (Heartbeat Buffer over-read bug)

15 2014-05-03
hmlio/vaas-cve-2014-0160

Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed

15 2019-10-08
hybridus/heartbleedscanner

Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)

11 2015-09-24
0x90/CVE-2014-0160

Heartbleed variants

8 2014-05-09
DominikTo/bleed

bleed is a tool to test servers for the 'Heartbleed' vulnerability (CVE-2014-0160).

7 2014-04-17
0xinf0/bleeding_onions

Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160

6 2014-04-13
hreese/heartbleed-dtls

POC for CVE-2014-0160 (Heartbleed) for DTLS

5 2016-03-26
anthophilee/A2SV--SSL-VUL-Scan

A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous Cipher

5 2021-01-01
undacmic/heartbleed-proof-of-concept

Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:

5 2023-01-18
yryz/heartbleed.js

openssl Heartbleed bug(CVE-2014-0160) check for Node.js

4 2015-04-30
mozilla-services/Heartbleed

A checker (site and tool) for CVE-2014-0160

3 2019-03-27
ingochris/heartpatch.us

OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.

3 2021-02-14
cyphar/heartthreader

Mass, multithreaded testing for servers against Heartbleed (CVE-2014-0160).

2 2014-05-29
zouguangxian/heartbleed

Checks for vulnerabilities: CVE-2014-0160

2 2014-04-10
amerine/coronary

Test CIDR blocks for CVE-2014-0160/Heartbleed

2 2014-04-10
waqasjamal-zz/HeartBleed-Vulnerability-Checker

This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.

2 2014-04-11
pblittle/aws-suture

OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.

2 2014-09-25
cheese-hub/heartbleed

Demonstration of the Heartbleed Bug CVE-2014-0160

2 2019-06-27
GuillermoEscobero/heartbleed

CVE-2014-0160 OpenSSL Heartbleed Proof of Concept

2 2020-12-14
GardeniaWhite/fuzzing

fuzzing with libFuzzer,inlude openssl heartbleed (CVE-2014-0160)

2 2022-05-07
indrajeetmp11/Heartbleed-PoC-Exploit-Script

This Python PoC script detects the Heartbleed vulnerability (CVE-2014-0160) by performing a TLS handshake with heartbeat extension and sending a craft

2 2025-11-17
proactiveRISK/heartbleed-extention

A firefox extension and checker for CVE-2014-0160

1 2014-04-11
sammyfung/openssl-heartbleed-fix

OpenSSL Heartbleed (CVE-2014-0160) Fix script

1 2014-04-10
xlucas/heartbleed

A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability

1 2015-05-02
vortextube/ssl_scanner

Heartbleed (CVE-2014-0160) SSLv3 Scanner

1 2014-10-12
xanas/heartbleed.py

#!/usr/bin/python # Modified by Travis Lee # -changed output to display text only instead of hexdump and made it easier to read # -added option to sp

1 2015-04-05
1 2016-02-16
Saymeis/HeartBleed

CVE-2014-0160

1 2019-05-19
belmind/heartbleed

A collection of scripts and instructions to test CVE-2014-0160 (heartbleed). ❤️ 🩸

1 2021-05-20
fb1h2s/CVE-2014-0160

openssl Heart Bleed Exploit: CVE-2014-0160 Mass Security Auditor

0 2014-04-08
takeshixx/ssl-heartbleed.nse

Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160

0 2014-04-13
roganartu/heartbleedchecker-chrome

Chrome extension that automatically checks visited sites for vulnerability to OpenSSL CVE-2014-0160

0 2014-04-09
siddolo/knockbleed

CVE-2014-0160 mass test against subdomains

0 2014-04-10
a0726h77/heartbleed-test

CVE-2014-0160 scanner

0 2014-04-12
idkqh7/heatbleeding

Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)

0 2014-04-09
GeeksXtreme/ssl-heartbleed.nse

Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.

0 2014-04-13
indiw0rm/-Heartbleed-

A checker (site and tool) for CVE-2014-0160:

0 2014-04-15
iSCInc/heartbleed

A checker (site and tool) for CVE-2014-0160. Software from @FiloSottile for iSC Inc..

0 2015-05-15
froyo75/Heartbleed_Dockerfile_with_Nginx

Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.

0 2021-08-28
caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC

来自:https://www.freebuf.com/articles/web/31700.html

0 2018-11-08
0 2021-04-15
tomdevman/heartbleed-bug

Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔

0 2019-04-10
ThanHuuTuan/Heartexploit

Aquí está mi nuevo y primer exploit web, este exploit ataca a la vulnerabilidad de HeartBleed (CVE-2014-0160) espero que os guste.

0 2018-05-07
rouze-d/heartbleed

Simple OpenSSL TLS Heartbeat (CVE-2014-0160) Scanner and Exploit (Multiple SSL/TLS versions)

0 2020-07-04
pierceoneill/bleeding-heart

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of th

0 2021-08-15
cbk914/heartbleed-checker

Check for CVE-2014-0160

0 2024-05-17
Shayhha/HeartbleedAttack

This is the Heratbleed bug (CVE-2014-0160) documentation I did for Advenced Cyber Attacks course.

0 2025-12-03
ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

The objective of this project was to assess a remote host for the Heartbleed vulnerability (CVE-2014-0160), verify its presence, and exploit it to ext

0 2025-06-27
SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

Heartbleed (CVE-2014-0160) was devastating because it leaked adjacent memory. CTT-Heartbleed goes further—it uses 33-layer temporal resonance to map,

0 2026-01-28
0 2026-03-05
Ryo-Soikutsu/Heartbleed

Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for educational

0 2026-03-22
71 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
95%
EPSS 94.46%
CVSS v3.1 7.5
Mentions 7
Last Seen May 01, 2015

CNA Information

CNA Assigner
redhat

Analyst Note

CVE-2014-0160 (Heartbleed) is a canonical zero-day: a critical OpenSSL TLS heartbeat implementation flaw exploited in the wild before patches were available in April 2014. Multiple authoritative sources explicitly label it as a zero-day, and contemporaneous reports document widespread exploitation affecting millions of websites and devices immediately upon discovery.

Threat Actors 2

Careto
apt_group Information theft and espionage 🇪🇸 ES
Comment Crew
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 20, 2026
Published DateApr 07, 2014