* DTLS segmentation fault in dtls1_get_record (only impacts people who use DTLS, and is a null pointer deref, which usually isn't exploitable)
* DTLS memory leak in dtls1_buffer_record (same, and only exhausts memory)
* no-ssl3 configuration sets method to NULL (a non-standard build produces a null pointer crash in SSL3 negotiation)
* ECDHE silently downgrades to ECDH (this looks like a server can in an oddball situation lie about forward secrecy --- also, this only impacts OpenSSL clients, like curl)
* RSA silently downgrades to EXPORT_RSA (a server can sabotage the security of a session, which it can do in a variety of other ways anyways --- also, this only impacts OpenSSL clients, like curl)
* DH client certificates accepted without verification (breaks client authentication, which not many people rely on, but only affects servers that (a) do TLS client auth and (b) trust DH-key-issuing CAs, which are "extremely rare and hardly ever encountered")
* Certificate fingerprints can be modified (this one I actually wonder about the sev:lo on; it's low because it doesn't impact browsers, but certificate blacklists are common in enterprise software)
* Bignum squaring may produce incorrect results (this is just weird)