CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
70195 | CVE-2014-2900 | Candidate | wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate. | Assigned (20140418) | None (candidate not yet proposed) | View | |
70194 | CVE-2014-2899 | Candidate | wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found. | Assigned (20140418) | None (candidate not yet proposed) | View | |
85021 | CVE-2015-7744 | Candidate | wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack. | Assigned (20151007) | None (candidate not yet proposed) | View | |
84202 | CVE-2015-6925 | Candidate | wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message. | Assigned (20150912) | None (candidate not yet proposed) | View | |
42247 | CVE-2009-4812 | Candidate | Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message. | Assigned (20100427) | None (candidate not yet proposed) | View |
Page 154 of 20943, showing 5 records out of 104715 total, starting on record 766, ending on 770