{"api_version":"1","generated_at":"2026-07-23T06:08:27+00:00","cve":"CVE-2014-2896","urls":{"html":"https://cve.report/CVE-2014-2896","api":"https://cve.report/api/cve/CVE-2014-2896.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-2896","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-2896"},"summary":{"title":"CVE-2014-2896","description":"The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-01-28 16:15:00","updated_at":"2020-02-04 19:15:00"},"problem_types":["CWE-125"],"metrics":[],"references":[{"url":"http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html","name":"http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"wolfSSL Security Advisory: April 9, 2014 - wolfSSL","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/oss-sec/2014/q2/126","name":"http://seclists.org/oss-sec/2014/q2/126","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-sec: CVE ids for CyaSSL 2.9.4?","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html","name":"http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"wolfSSL - Docs | CyaSSL ChangeLog","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/oss-sec/2014/q2/130","name":"http://seclists.org/oss-sec/2014/q2/130","refsource":"MISC","tags":["Mailing List","Third Party Advisory"],"title":"oss-sec: Re: CVE ids for CyaSSL 2.9.4?","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-2896","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-2896","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"2896","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wolfssl","cpe5":"wolfssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"2896","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wolfssl","cpe5":"wolfssl","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-2896","STATE":"PUBLIC"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"references":{"reference_data":[{"refsource":"CONFIRM","name":"http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html","url":"http://www.wolfssl.com/yaSSL/Blog/Entries/2014/4/11_wolfSSL_Security_Advisory__April_9%2C_2014.html"},{"refsource":"CONFIRM","name":"http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html","url":"http://www.wolfssl.com/yaSSL/Docs-cyassl-changelog.html"},{"refsource":"MISC","name":"http://seclists.org/oss-sec/2014/q2/126","url":"http://seclists.org/oss-sec/2014/q2/126"},{"refsource":"MISC","name":"http://seclists.org/oss-sec/2014/q2/130","url":"http://seclists.org/oss-sec/2014/q2/130"}]}},"nvd":{"publishedDate":"2020-01-28 16:15:00","lastModifiedDate":"2020-02-04 19:15:00","problem_types":["CWE-125"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*","versionStartIncluding":"2.5.0","versionEndExcluding":"2.9.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"2896","Ordinal":"69838","Title":"CVE-2014-2896","CVE":"CVE-2014-2896","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"2896","Ordinal":"1","NoteData":"The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact and vectors, which trigger memory corruption or an out-of-bounds read.","Type":"Description","Title":null},{"CveYear":"2014","CveId":"2896","Ordinal":"2","NoteData":"2020-01-28","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"2896","Ordinal":"3","NoteData":"2020-01-28","Type":"Other","Title":"Modified"}]}}}