Show filters
112 Total Results
Displaying 101-110 of 112
Sort by:
Attacker Value
Unknown
CVE-2015-6567
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality.
0
Attacker Value
Unknown
CVE-2017-6076
Disclosure Date: February 24, 2017 (last updated November 26, 2024)
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.
0
Attacker Value
Unknown
CVE-2016-7440
Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
0
Attacker Value
Unknown
CVE-2016-7438
Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
0
Attacker Value
Unknown
CVE-2016-7439
Disclosure Date: December 13, 2016 (last updated November 25, 2024)
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
0
Attacker Value
Unknown
CVE-2015-6925
Disclosure Date: January 22, 2016 (last updated November 25, 2024)
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
0
Attacker Value
Unknown
CVE-2015-7744
Disclosure Date: January 22, 2016 (last updated November 25, 2024)
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.
0
Attacker Value
Unknown
CVE-2012-1897
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in Wolf CMS 0.75 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) delete users via the user id number to admin/user/delete; (2) delete pages via the page id number to admin/page/delete; delete the (3) images or (4) themes directory via the directory name to admin/plugin/file_manager/delete, and possibly other directories; or (5) logout the user via a request to admin/login/logout.
0
Attacker Value
Unknown
CVE-2012-1898
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user[name], (2) user[email], or (3) user[username] parameters.
0
Attacker Value
Unknown
CVE-2006-6778
Disclosure Date: December 28, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in shownews.php in TimberWolf 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the nid parameter.
0