CVE-2014-2898
- EPSS 1.01%
- Veröffentlicht 28.01.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 02:07:09
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not checking the return code and MAC verification fail...
CVE-2014-2897
- EPSS 1.01%
- Veröffentlicht 28.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:07:09
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMAC, which triggers an out-of-bounds read.
CVE-2014-2896
- EPSS 1.01%
- Veröffentlicht 28.01.2020 16:15:11
- Zuletzt bearbeitet 21.11.2024 02:07:09
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.
CVE-2019-19963
- EPSS 0.36%
- Veröffentlicht 25.12.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:45
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modular inversion of the nonce, leading to a side-channel attack against the nonce.
CVE-2019-19962
- EPSS 0.18%
- Veröffentlicht 25.12.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:45
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.
CVE-2019-19960
- EPSS 0.36%
- Veröffentlicht 25.12.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:35:45
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
CVE-2019-14317
- EPSS 0.39%
- Veröffentlicht 11.12.2019 18:16:18
- Zuletzt bearbeitet 21.11.2024 04:26:28
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term private key from several hundred DSA signatures via a lattice attack. The issue occurs because dsa.c...
CVE-2014-2904
- EPSS 0.23%
- Veröffentlicht 21.11.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:07:10
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
CVE-2014-2902
- EPSS 0.22%
- Veröffentlicht 21.11.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:07:10
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
CVE-2014-2901
- EPSS 0.13%
- Veröffentlicht 21.11.2019 23:15:11
- Zuletzt bearbeitet 21.11.2024 02:07:09
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.