5

CVE-2014-8564

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted (1) Elliptic Curve Cryptography (ECC) certificate or (2) certificate signing requests (CSR), related to generating key IDs.

Data is provided by the National Vulnerability Database (NVD)
GnuGnutls Version3.0
GnuGnutls Version3.0.0
GnuGnutls Version3.0.1
GnuGnutls Version3.0.2
GnuGnutls Version3.0.3
GnuGnutls Version3.0.4
GnuGnutls Version3.0.5
GnuGnutls Version3.0.6
GnuGnutls Version3.0.7
GnuGnutls Version3.0.8
GnuGnutls Version3.0.9
GnuGnutls Version3.0.10
GnuGnutls Version3.0.11
GnuGnutls Version3.0.12
GnuGnutls Version3.0.13
GnuGnutls Version3.0.14
GnuGnutls Version3.0.15
GnuGnutls Version3.0.16
GnuGnutls Version3.0.17
GnuGnutls Version3.0.18
GnuGnutls Version3.0.19
GnuGnutls Version3.0.20
GnuGnutls Version3.0.21
GnuGnutls Version3.0.22
GnuGnutls Version3.0.23
GnuGnutls Version3.0.24
GnuGnutls Version3.0.25
GnuGnutls Version3.0.26
GnuGnutls Version3.0.27
GnuGnutls Version3.0.28
GnuGnutls Version3.1.0
GnuGnutls Version3.1.1
GnuGnutls Version3.1.2
GnuGnutls Version3.1.3
GnuGnutls Version3.1.4
GnuGnutls Version3.1.5
GnuGnutls Version3.1.6
GnuGnutls Version3.1.7
GnuGnutls Version3.1.8
GnuGnutls Version3.1.9
GnuGnutls Version3.1.10
GnuGnutls Version3.1.11
GnuGnutls Version3.1.12
GnuGnutls Version3.1.13
GnuGnutls Version3.1.14
GnuGnutls Version3.1.15
GnuGnutls Version3.1.16
GnuGnutls Version3.1.17
GnuGnutls Version3.1.18
GnuGnutls Version3.1.19
GnuGnutls Version3.1.20
GnuGnutls Version3.1.21
GnuGnutls Version3.1.22
GnuGnutls Version3.1.23
GnuGnutls Version3.1.24
GnuGnutls Version3.1.25
GnuGnutls Version3.1.26
GnuGnutls Version3.1.27
GnuGnutls Version3.2.0
GnuGnutls Version3.2.1
GnuGnutls Version3.2.2
GnuGnutls Version3.2.3
GnuGnutls Version3.2.4
GnuGnutls Version3.2.5
GnuGnutls Version3.2.6
GnuGnutls Version3.2.7
GnuGnutls Version3.2.8
GnuGnutls Version3.2.8.1
GnuGnutls Version3.2.9
GnuGnutls Version3.2.10
GnuGnutls Version3.2.11
GnuGnutls Version3.2.12
GnuGnutls Version3.2.12.1
GnuGnutls Version3.2.13
GnuGnutls Version3.2.14
GnuGnutls Version3.2.15
GnuGnutls Version3.2.16
GnuGnutls Version3.2.17
GnuGnutls Version3.2.18
GnuGnutls Version3.2.19
GnuGnutls Version3.3.0 Update-
GnuGnutls Version3.3.0 Updatepre0
GnuGnutls Version3.3.1
GnuGnutls Version3.3.2
GnuGnutls Version3.3.3
GnuGnutls Version3.3.4
GnuGnutls Version3.3.5
GnuGnutls Version3.3.6
GnuGnutls Version3.3.7
GnuGnutls Version3.3.8
GnuGnutls Version3.3.9
OpensuseOpensuse Version12.3
OpensuseOpensuse Version13.1
OpensuseOpensuse Version13.2
CanonicalUbuntu Linux Version14.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.81% 0.72
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P