Products: 3
    Vulnerabilities: 8
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-2899

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.

    Last Modified: Apr 12, 2025
    Published: Apr 22, 2014

    CVE-2014-2900

    wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.

    Last Modified: Apr 12, 2025
    Published: Apr 22, 2014

    CVE-2013-1623

    yaSSL: TLS CBC padding timing attack

    Last Modified: Apr 11, 2025
    Published: Feb 04, 2013

    CVE-2012-1558

    yaSSL CyaSSL before 2.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted X.509 certificate.

    Last Modified: Apr 11, 2025
    Published: Mar 12, 2012

    CVE-2011-2900

    Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.

    Last Modified: Apr 11, 2025
    Published: Aug 05, 2011
    Items Per Page
    Yassl Vulnerabilities & Security CVEs | CVE-DB