|
283071
|
9.8 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an o…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-2896
|
2024-11-21 11:07 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283072
|
7.5 |
HIGH
Network
|
publify_project
|
publify
|
Publify before 8.0.1 is vulnerable to a Denial of Service attack
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-3211
|
2024-11-21 11:07 |
2020-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283073
|
8.8 |
HIGH
Network
|
dlink
|
dwr-113_firmware
|
Cross-site request forgery (CSRF) vulnerability in D-Link DWR-113 (Rev. Ax) with firmware before 2.03b02 allows remote attackers to hijack the authentication of administrators for requests that chang…
|
CWE-352
Origin Validation Error
|
CVE-2014-3136
|
2024-11-21 11:07 |
2019-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283074
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.
|
CWE-287
Improper Authentication
|
CVE-2014-2904
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283075
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-2902
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283076
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.
|
CWE-295
Improper Certificate Validation
|
CVE-2014-2901
|
2024-11-21 11:07 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283077
|
9.1 |
CRITICAL
Network
|
linux google
|
linux_kernel chrome_os
|
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting com…
|
CWE-125
Out-of-bounds Read
|
CVE-2014-3180
|
2024-11-21 11:07 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283078
|
9.8 |
CRITICAL
Network
|
ezpz-one-click-backup_project
|
ezpz-one-click-backup
|
The EZPZ One Click Backup (ezpz-one-click-backup) plugin 12.03.10 and earlier for WordPress allows remote attackers to execute arbitrary commands via the cmd parameter to functions/ezpz-archive-cmd.p…
|
CWE-77
Command Injection
|
CVE-2014-3114
|
2024-11-21 11:07 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283079
|
7.1 |
HIGH
Local
|
truecrypt_project
|
truecrypt
|
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLength value in the MainThreadProc function in Encrypt…
|
CWE-200 CWE-190 CWE-400
Information Exposure Integer Overflow or Wraparound Uncontrolled Resource Consumption
|
CVE-2014-2885
|
2024-11-21 11:07 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283080
|
3.3 |
LOW
Local
|
truecrypt_project
|
truecrypt
|
The ProcessVolumeDeviceControlIrp function in Ntdriver.c in TrueCrypt 7.1a allows local users to bypass access restrictions and obtain sensitive information about arbitrary files via a (1) TC_IOCTL_O…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2014-2884
|
2024-11-21 11:07 |
2018-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|