latchset kayıtları
latchset üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption2
- CWE-1300 Improper Protection of Physical Side Channels1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2023-6258İstismar yok | Pkcs11-provider: side-channel proofing pkcs#1 1.5 pathslatchset · pkcs11-provider · CWE-1300 | Yüksek8,1 | — | %0,6 | 30 Oca 2024 |
30İzleyin | CVE-2023-50967İstismar yok | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.latchset · jose · CWE-400 | Yüksek7,5 | — | %1,4 | 20 Mar 2024 |
27İzleyin | CVE-2024-28102İstismar yok | JWCrypto vulnerable to JWT bomb Attack in `deserialize` functionlatchset · jwcrypto · CWE-770 | Orta6,8 | — | %1,0 | 20 Mar 2024 |
22İzleyin | CVE-2016-6298İstismar yok | The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, wlatchset · jwcrypto · CWE-200 | Orta5,3 | — | %2,2 | 1 Eyl 2016 |
21İzleyin | CVE-2023-6681İstismar yok | Jwcrypto: denail of service via specifically crafted jwelatchset · jwcrypto · CWE-400 | Orta5,3 | — | %0,9 | 12 Şub 2024 |
21İzleyin | CVE-2026-39373İstismar yok | JWCrypto: JWE ZIP decompression bomblatchset · jwcrypto · CWE-409 | Orta5,3 | — | %0,4 | 7 Nis 2026 |
- CVE-2023-625832İzleyin
Pkcs11-provider: side-channel proofing pkcs#1 1.5 paths
YüksekCVSS 8,1İstismar yokEPSS %1latchset · pkcs11-provider30 Oca 2024
- CVE-2023-5096730İzleyin
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
YüksekCVSS 7,5İstismar yokEPSS %1latchset · jose20 Mar 2024
- CVE-2024-2810227İzleyin
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
OrtaCVSS 6,8İstismar yokEPSS %1latchset · jwcrypto20 Mar 2024
- CVE-2016-629822İzleyin
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, w
OrtaCVSS 5,3İstismar yokEPSS %2latchset · jwcrypto1 Eyl 2016
- CVE-2023-668121İzleyin
Jwcrypto: denail of service via specifically crafted jwe
OrtaCVSS 5,3İstismar yokEPSS %1latchset · jwcrypto12 Şub 2024
- CVE-2026-3937321İzleyin
JWCrypto: JWE ZIP decompression bomb
OrtaCVSS 5,3İstismar yokEPSS %0latchset · jwcrypto7 Nis 2026