İçeriğe atla
Noroxi

Connect2id kayıtları

connect2id üreticisine ait 5 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

5 kayıt
  • CVE-2019-17195
    42Planlayın

    Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash

    KritikCVSS 9,8Kavram kanıtıEPSS %11

    connect2id · nimbus jose\+jwt15 Eki 2019

  • CVE-2017-12974
    30İzleyin

    Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve

    YüksekCVSS 7,5İstismar yokEPSS %1

    connect2id · nimbus jose\+jwt20 Ağu 2017

  • CVE-2017-12972
    30İzleyin

    In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers

    YüksekCVSS 7,5İstismar yokEPSS %1

    connect2id · nimbus jose\+jwt20 Ağu 2017

  • CVE-2023-52428
    30İzleyin

    In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header val

    YüksekCVSS 7,5İstismar yokEPSS %1

    connect2id · nimbus jose\+jwt11 Şub 2024

  • CVE-2017-12973
    12İzleyin

    Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attacke

    DüşükCVSS 3,1İstismar yokEPSS %1

    connect2id · nimbus jose\+jwt20 Ağu 2017