CVE-2014-0160: Heartbleed
What is the Heartbleed vulnerability?
A buffer over-read vulnerability in OpenSSL's TLS Heartbeat extension. Attackers can read up to 64KB of server memory per request, potentially exposing private keys, session tokens, passwords, and other sensitive data in transit.
Impact & Exploitation
Affected approximately 17% (500,000+) of all SSL/TLS web servers at disclosure. Private keys, user credentials, and session cookies were extractable. Many organizations had to reissue SSL certificates.
How Precogs AI Detects Heartbleed
Precogs AI Binary SAST detects vulnerable OpenSSL versions compiled into binaries, firmware, and IoT devices — critical for embedded systems where OpenSSL is statically linked and not updated through package managers.