I do not understand some of ths. Is the vulnerabilities relatrd to new version of openSSL or hjave they always been there but someone finally figuird out an exploit(s) ?
From what I read, these vulnerabilities were there for years.
The public finally figured them out, but for all we know someone could have just as well planted them there, on which case he'd have an exploit(s) ever since.
After the heartbleed incident, people have finally started to seriously audit this code.
These are just the first findings - I'm betting more will come.