CVE-2014-2899

EUVD-2014-2922
wolfSSL CyaSSL before 2.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a request for the peer certificate when a certificate parsing failure occurs or (2) a client_key_exchange message when the ephemeral key is not found.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
Affected Products (NVD)
VendorProductVersion
yasslcyassl
𝑥
≤ 2.9.0
yasslcyassl
0.2.0
yasslcyassl
0.3.0
yasslcyassl
0.4.0
yasslcyassl
0.5.0
yasslcyassl
0.5.5
yasslcyassl
0.6.0
yasslcyassl
0.6.2
yasslcyassl
0.6.3
yasslcyassl
0.8.0
yasslcyassl
0.9.0
yasslcyassl
0.9.6
yasslcyassl
0.9.8
yasslcyassl
0.9.9
yasslcyassl
1.0.0:rc1
yasslcyassl
1.0.0:rc2
yasslcyassl
1.0.0:rc3
yasslcyassl
1.0.2
yasslcyassl
1.0.3
yasslcyassl
1.0.6
yasslcyassl
1.1.0
yasslcyassl
1.2.0
yasslcyassl
1.3.0
yasslcyassl
1.4.0
yasslcyassl
1.5.0
yasslcyassl
1.5.4
yasslcyassl
1.5.6
yasslcyassl
1.6.0
yasslcyassl
1.6.5
yasslcyassl
1.8.0
yasslcyassl
1.9.0
yasslcyassl
2.0.0:rc1
yasslcyassl
2.0.0:rc2
yasslcyassl
2.0.0:rc3
yasslcyassl
2.0.2
yasslcyassl
2.0.6
yasslcyassl
2.0.8
yasslcyassl
2.2.0
yasslcyassl
2.3.0
yasslcyassl
2.4.0
yasslcyassl
2.4.6
yasslcyassl
2.5.0
yasslcyassl
2.6.0
yasslcyassl
2.7.0
yasslcyassl
2.8.0
𝑥
= Vulnerable software versions