VendorsyaSSLcyassl2.4.6
Vulnerabilities

yaSSL CyaSSL 2.4.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2014-2900
wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers to spoof servers via crafted X.509 certificate.
Published 2014-04-22 · Modified
5.8EPSS 0.010
CVE-2014-2899
wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.
Published 2014-04-22 · Modified
5.0EPSS 0.018