Anatomy of OpenSSL's Heartbleed: Just four bytes trigger

Unlike Heartbleed, DROWN is a bug in the underlying SSLv2 protocol, Chris Czub, security research engineer at Duo Security, explained.

The Heartbleed flaw in OpenSSL. The fatal flaw (that has been named Heartbleed) is that the OpenSSL library never checked that the Heartbeat payload size corresponds with the actual length of the payload being sent. A user is allowed to input any number up to 65535 (64 …

Heartbleed is a play on words referring to an extension on OpenSSL called "heartbeat." The protocol is used to keep connections open, even when data isn't being shared between those connections.