NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
64850 | CVE-2006-6289 | Woltlab Burning Board (wBB) Lite 1.0.2 does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter"s hash value, which allows remote attackers to execute arbitrary SQL commands via the wbb_userid parameter to the top-level URI. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in wBB Lite. | 2 | 6.8 | Medium | 2016-12-20 | 2008-09-05 | View | |
31218 | CVE-2014-2900 | wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate. | 2 | 5.8 | Medium | 2017-01-19 | 2017-01-03 | View | |
31217 | CVE-2014-2899 | wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found. | 2 | 5 | Medium | 2017-01-19 | 2017-01-03 | View | |
86101 | CVE-2017-8855 | wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key. | 2 | 5 | Medium | 2017-05-27 | 2017-05-17 | View | |
86100 | CVE-2017-8854 | wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file. | 2 | 6.8 | Medium | 2017-05-27 | 2017-05-17 | View |
Page 174 of 17672, showing 5 records out of 88360 total, starting on record 866, ending on 870