CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70195  CVE-2014-2900  Candidate  wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.  Assigned (20140418)  None (candidate not yet proposed)    View
70194  CVE-2014-2899  Candidate  wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.  Assigned (20140418)  None (candidate not yet proposed)    View
85021  CVE-2015-7744  Candidate  wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.  Assigned (20151007)  None (candidate not yet proposed)    View
84202  CVE-2015-6925  Candidate  wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.  Assigned (20150912)  None (candidate not yet proposed)    View
42247  CVE-2009-4812  Candidate  Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message.  Assigned (20100427)  None (candidate not yet proposed)    View

Page 154 of 20943, showing 5 records out of 104715 total, starting on record 766, ending on 770

Actions