openpgpjs kayıtları
openpgpjs üreticisine ait 5 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-310 Cryptographic Issues1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
5 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
31İzleyin | CVE-2015-8013İstismar yok | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass aopenpgpjs · openpgpjs · CWE-310 | Yüksek7,5 | — | %3,9 | 25 Tem 2017 |
31İzleyin | CVE-2019-9153Kavram kanıtı | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatopenpgpjs · openpgpjs · CWE-347 | Yüksek7,5 | — | %2,0 | 22 Ağu 2019 |
30İzleyin | CVE-2019-9154İstismar yok | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.openpgpjs · openpgpjs · CWE-347 | Yüksek7,5 | — | %1,6 | 22 Ağu 2019 |
23İzleyin | CVE-2019-9155İstismar yok | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptioopenpgpjs · openpgpjs · CWE-327 | Orta5,9 | — | %1,5 | 22 Ağu 2019 |
17İzleyin | CVE-2023-41037İstismar yok | Cleartext Signed Message Signature Spoofing in openpgpjsopenpgpjs · openpgpjs · CWE-347 | Orta4,3 | — | %0,4 | 29 Ağu 2023 |
- CVE-2015-801331İzleyin
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass a
YüksekCVSS 7,5İstismar yokEPSS %4openpgpjs · openpgpjs25 Tem 2017
- CVE-2019-915331İzleyin
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signat
YüksekCVSS 7,5Kavram kanıtıEPSS %2openpgpjs · openpgpjs22 Ağu 2019
- CVE-2019-915430İzleyin
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
YüksekCVSS 7,5İstismar yokEPSS %2openpgpjs · openpgpjs22 Ağu 2019
- CVE-2019-915523İzleyin
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptio
OrtaCVSS 5,9İstismar yokEPSS %1openpgpjs · openpgpjs22 Ağu 2019
- CVE-2023-4103717İzleyin
Cleartext Signed Message Signature Spoofing in openpgpjs
OrtaCVSS 4,3İstismar yokEPSS %0openpgpjs · openpgpjs29 Ağu 2023