NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
21856  CVE-2016-7444  The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.    Medium  2017-03-29  2017-03-24  View
21855  CVE-2016-7442  The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.    2.1  Low  2017-01-19  2016-11-28  View
21854  CVE-2016-7440  The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.    2.1  Low  2017-01-19  2017-01-06  View
21853  CVE-2016-7439  The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.    2.1  Low  2017-01-19  2016-12-23  View
21852  CVE-2016-7438  The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.    2.1  Low  2017-01-19  2016-12-23  View

Page 1277 of 17672, showing 5 records out of 88360 total, starting on record 6381, ending on 6385

Actions