← Back

CVE-2014-8628

nvd nist
Published: Aug 24, 2015Modified: May 6, 2026

JSON object

Loading...
7.8
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:C
Exploitability: 10.0 / Impact: 6.9
Source: NVD

Description

Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different affected versions. See CVE-2014-9744 for the ClientHello message issue.

Affected (10)

Products: Polarssl: Polarssl
1 product
Polarssl
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Polarssl
Up to 1.2.11
Version 1.3.0
Version 1.3.1
Version 1.3.2
Version 1.3.3
Version 1.3.4
Version 1.3.5
Version 1.3.6
Version 1.3.7
Version 1.3.8

Related CWEs

Timeline

No history available yet.