Skip to content
Noroxi

CWE-385 · 35 records

Covert Timing Channel

CVEs in this class

35 records

  • Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable T

    CriticalCVSS 9.8No exploitEPSS 1%

    dell · bsafe crypto-c-micro-editionJul 11, 2022

  • Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim

    CriticalCVSS 9.8No exploitEPSS 1%

    dell · bsafe crypto-c-micro-editionJul 11, 2022

  • CVE-2026-5598
    35Monitor

    Non-constant time comparisons risk private key leakage in FrodoKEM.

    HighCVSS 8.9No exploitEPSS 1%

    legion of the bouncy castle inc. · bc-javaApr 15, 2026

  • Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim

    HighCVSS 8.1No exploitEPSS 1%

    dell · bsafe crypto-c-micro-editionJul 11, 2022

  • Observable Timing Discrepancy in pypqc

    HighCVSS 8.2No exploit

    PyPI · pypqcJun 5, 2024

  • CVE-2023-3640
    31Monitor

    Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the p

    HighCVSS 7.8Proof of conceptEPSS 1%

    linux · linux kernelJul 24, 2023

  • CVE-2019-3732
    30Monitor

    RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite

    HighCVSS 7.5No exploitEPSS 1%

    dell · bsafe crypto-c-micro-editionSep 30, 2019

  • Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the a

    HighCVSS 7.5No exploitEPSS 1%

    dell · bsafe ssl-jFeb 23, 2022

  • Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.

    HighCVSS 7.5No exploitEPSS 1%

    dell · powerscale onefsMar 25, 2024

  • vLLM vulnerable to timing attack at bearer auth

    HighCVSS 7.5No exploitEPSS 1%

    vllm · vllmOct 7, 2025

  • Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are

    HighCVSS 7.4No exploitEPSS 1%

    nodejs · nodeSep 7, 2024

  • CVE-2025-0306
    29Monitor

    Ruby: openssl: ruby marvin attack

    HighCVSS 7.4No exploitEPSS 1%

    red hat · red hat enterprise linux 10Jan 9, 2025

  • CVE-2017-2624
    28Monitor

    It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.

    HighCVSS 7.0No exploitEPSS 1%

    x.org · x serverJul 27, 2018

  • CVE-2025-9231
    27Monitor

    Timing side-channel in SM2 algorithm on 64 bit ARM

    MediumCVSS 6.5No exploitEPSS 2%

    openssl · opensslSep 30, 2025

  • CVE-2026-6478
    26Monitor

    PostgreSQL discloses MD5-hashed passwords via covert timing channel

    MediumCVSS 6.5No exploitEPSS 1%

    postgresql · postgresqlMay 14, 2026

  • It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.

    MediumCVSS 5.9No exploitEPSS 4%

    gnu · gnutlsAug 22, 2018

  • It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.

    MediumCVSS 5.9No exploitEPSS 4%

    gnu · gnutlsAug 22, 2018

  • python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5

    MediumCVSS 5.9No exploitEPSS 2%

    cryptography.io · cryptographyJan 11, 2021

  • A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API

    MediumCVSS 5.9No exploitEPSS 2%

    m2crypto project · m2cryptoJan 12, 2021

  • It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.

    MediumCVSS 5.9No exploitEPSS 2%

    python-rsa project · python-rsaNov 12, 2020

  • CVE-2024-2236
    23Monitor

    Libgcrypt: vulnerable to marvin attack

    MediumCVSS 5.9No exploitEPSS 1%

    red hat · red hat enterprise linux 9Mar 6, 2024

  • iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption

    MediumCVSS 5.9No exploitEPSS 1%

    es · iperf3May 14, 2024

  • RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels

    MediumCVSS 5.9No exploitEPSS 1%

    rustcrypto · rsaNov 28, 2023

  • CVE-2016-7056
    22Monitor

    A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 priva

    MediumCVSS 5.5No exploitEPSS 1%

    openssl · opensslSep 10, 2018

  • A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.

    MediumCVSS 5.6No exploitEPSS 0%

    gnu · gnutlsAug 22, 2018

All vulnerability classes