NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
21856 | CVE-2016-7444 | The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc. | 2 | 5 | Medium | 2017-03-29 | 2017-03-24 | View | |
21855 | CVE-2016-7442 | The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab. | 2 | 2.1 | Low | 2017-01-19 | 2016-11-28 | View | |
21854 | CVE-2016-7440 | The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences. | 2 | 2.1 | Low | 2017-01-19 | 2017-01-06 | View | |
21853 | CVE-2016-7439 | The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-23 | View | |
21852 | CVE-2016-7438 | The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-23 | View |
Page 1277 of 17672, showing 5 records out of 88360 total, starting on record 6381, ending on 6385