Lucene search

K
nvd[email protected]NVD:CVE-2014-8628
HistoryAug 24, 2015 - 3:59 p.m.

CVE-2014-8628

2015-08-2415:59:00
CWE-399
web.nvd.nist.gov
7

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.3

Confidence

Low

EPSS

0.009

Percentile

83.2%

Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.

Affected configurations

Nvd
Node
polarsslpolarsslRange1.2.11
OR
polarsslpolarsslMatch1.3.0
OR
polarsslpolarsslMatch1.3.1
OR
polarsslpolarsslMatch1.3.2
OR
polarsslpolarsslMatch1.3.3
OR
polarsslpolarsslMatch1.3.4
OR
polarsslpolarsslMatch1.3.5
OR
polarsslpolarsslMatch1.3.6
OR
polarsslpolarsslMatch1.3.7
OR
polarsslpolarsslMatch1.3.8
VendorProductVersionCPE
polarsslpolarssl*cpe:2.3:a:polarssl:polarssl:*:*:*:*:*:*:*:*
polarsslpolarssl1.3.0cpe:2.3:a:polarssl:polarssl:1.3.0:*:*:*:*:*:*:*
polarsslpolarssl1.3.1cpe:2.3:a:polarssl:polarssl:1.3.1:*:*:*:*:*:*:*
polarsslpolarssl1.3.2cpe:2.3:a:polarssl:polarssl:1.3.2:*:*:*:*:*:*:*
polarsslpolarssl1.3.3cpe:2.3:a:polarssl:polarssl:1.3.3:*:*:*:*:*:*:*
polarsslpolarssl1.3.4cpe:2.3:a:polarssl:polarssl:1.3.4:*:*:*:*:*:*:*
polarsslpolarssl1.3.5cpe:2.3:a:polarssl:polarssl:1.3.5:*:*:*:*:*:*:*
polarsslpolarssl1.3.6cpe:2.3:a:polarssl:polarssl:1.3.6:*:*:*:*:*:*:*
polarsslpolarssl1.3.7cpe:2.3:a:polarssl:polarssl:1.3.7:*:*:*:*:*:*:*
polarsslpolarssl1.3.8cpe:2.3:a:polarssl:polarssl:1.3.8:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

AI Score

6.3

Confidence

Low

EPSS

0.009

Percentile

83.2%