|
279531
|
9.8 |
CRITICAL
Network
|
fishshell
|
fish
|
fish (aka fish-shell) 2.0.0 before 2.1.1 does not restrict access to the configuration service (aka fish_config), which allows remote attackers to execute arbitrary code via unspecified vectors, as d…
|
CWE-20
Improper Input Validation
|
CVE-2014-2914
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279532
|
7.0 |
HIGH
Local
|
fishshell
|
fish
|
The psub function in fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly create temporary files, which allows local users to execute arbitrary commands via a temporary file with a predictable…
|
CWE-362
Race Condition
|
CVE-2014-2906
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279533
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-of-bounds read when an error occurs, related to not…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2898
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279534
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote attackers to have unspecified impact via a crafted HMA…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2897
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279535
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an o…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2896
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279536
|
7.5 |
HIGH
Network
|
publify_project
|
publify
|
Publify before 8.0.1 is vulnerable to a Denial of Service attack
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3211
|
2024-11-21 11:07 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279537
|
8.8 |
HIGH
Network
|
dlink
|
dwr-113_firmware
|
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that chang…
|
CWE-352
Origin Validation Error
|
CVE-2014-3136
|
2024-11-21 11:07 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279538
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
|
CWE-287
Improper Authentication
|
CVE-2014-2904
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279539
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-2902
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279540
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-2901
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|