CWE-385 · 35 records
Covert Timing Channel
CVEs in this class
35 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-29506No exploit | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Tdell · bsafe crypto-c-micro-edition · CWE-385 | Critical9.8 | — | 1.2% | Jul 11, 2022 |
39Monitor | CVE-2020-35166No exploit | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | Critical9.8 | — | 0.7% | Jul 11, 2022 |
35Monitor | CVE-2026-5598No exploit | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | High8.9 | — | 1.0% | Apr 15, 2026 |
32Monitor | CVE-2020-35164No exploit | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | High8.1 | — | 0.8% | Jul 11, 2022 |
32Monitor | GHSA-hvh4-5qr6-3v7rNo exploit | Observable Timing Discrepancy in pypqcPyPI · pypqc · CWE-385 | High8.2 | — | — | Jun 5, 2024 |
31Monitor | CVE-2023-3640Proof of concept | Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the plinux · linux kernel · CWE-385 | High7.8 | — | 0.8% | Jul 24, 2023 |
30Monitor | CVE-2019-3732No exploit | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suitedell · bsafe crypto-c-micro-edition · CWE-385 | High7.5 | — | 1.4% | Sep 30, 2019 |
30Monitor | CVE-2022-24409No exploit | Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the adell · bsafe ssl-j · CWE-385 | High7.5 | — | 1.0% | Feb 23, 2022 |
30Monitor | CVE-2024-25964No exploit | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.dell · powerscale onefs · CWE-385 | High7.5 | — | 0.7% | Mar 25, 2024 |
30Monitor | CVE-2025-59425No exploit | vLLM vulnerable to timing attack at bearer authvllm · vllm · CWE-385 | High7.5 | — | 0.6% | Oct 7, 2025 |
29Monitor | CVE-2023-46809No exploit | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched arenodejs · node · CWE-385 | High7.4 | — | 1.3% | Sep 7, 2024 |
29Monitor | CVE-2025-0306No exploit | Ruby: openssl: ruby marvin attackred hat · red hat enterprise linux 10 · CWE-385 | High7.4 | — | 0.6% | Jan 9, 2025 |
28Monitor | CVE-2017-2624No exploit | It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.x.org · x server · CWE-385 | High7.0 | — | 0.7% | Jul 27, 2018 |
27Monitor | CVE-2025-9231No exploit | Timing side-channel in SM2 algorithm on 64 bit ARMopenssl · openssl · CWE-385 | Medium6.5 | — | 2.2% | Sep 30, 2025 |
26Monitor | CVE-2026-6478No exploit | PostgreSQL discloses MD5-hashed passwords via covert timing channelpostgresql · postgresql · CWE-385 | Medium6.5 | — | 0.6% | May 14, 2026 |
24Monitor | CVE-2018-10844No exploit | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Medium5.9 | — | 3.6% | Aug 22, 2018 |
24Monitor | CVE-2018-10845No exploit | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Medium5.9 | — | 3.6% | Aug 22, 2018 |
24Monitor | CVE-2020-25659No exploit | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Medium5.9 | — | 2.4% | Jan 11, 2021 |
24Monitor | CVE-2020-25657No exploit | A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API m2crypto project · m2crypto · CWE-385 | Medium5.9 | — | 1.7% | Jan 12, 2021 |
23Monitor | CVE-2020-25658No exploit | It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.python-rsa project · python-rsa · CWE-385 | Medium5.9 | — | 1.7% | Nov 12, 2020 |
23Monitor | CVE-2024-2236No exploit | Libgcrypt: vulnerable to marvin attackred hat · red hat enterprise linux 9 · CWE-385 | Medium5.9 | — | 1.1% | Mar 6, 2024 |
23Monitor | CVE-2024-26306No exploit | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption es · iperf3 · CWE-385 | Medium5.9 | — | 1.1% | May 14, 2024 |
23Monitor | CVE-2023-49092No exploit | RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannelsrustcrypto · rsa · CWE-385 | Medium5.9 | — | 0.6% | Nov 28, 2023 |
22Monitor | CVE-2016-7056No exploit | A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 privaopenssl · openssl · CWE-385 | Medium5.5 | — | 0.6% | Sep 10, 2018 |
22Monitor | CVE-2018-10846No exploit | A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.gnu · gnutls · CWE-385 | Medium5.6 | — | 0.4% | Aug 22, 2018 |
- CVE-2020-2950639Monitor
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable T
CriticalCVSS 9.8No exploitEPSS 1%dell · bsafe crypto-c-micro-editionJul 11, 2022
- CVE-2020-3516639Monitor
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
CriticalCVSS 9.8No exploitEPSS 1%dell · bsafe crypto-c-micro-editionJul 11, 2022
- CVE-2026-559835Monitor
Non-constant time comparisons risk private key leakage in FrodoKEM.
HighCVSS 8.9No exploitEPSS 1%legion of the bouncy castle inc. · bc-javaApr 15, 2026
- CVE-2020-3516432Monitor
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
HighCVSS 8.1No exploitEPSS 1%dell · bsafe crypto-c-micro-editionJul 11, 2022
- GHSA-hvh4-5qr6-3v7r32Monitor
Observable Timing Discrepancy in pypqc
HighCVSS 8.2No exploitPyPI · pypqcJun 5, 2024
- CVE-2023-364031Monitor
Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the p
HighCVSS 7.8Proof of conceptEPSS 1%linux · linux kernelJul 24, 2023
- CVE-2019-373230Monitor
RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite
HighCVSS 7.5No exploitEPSS 1%dell · bsafe crypto-c-micro-editionSep 30, 2019
- CVE-2022-2440930Monitor
Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the a
HighCVSS 7.5No exploitEPSS 1%dell · bsafe ssl-jFeb 23, 2022
- CVE-2024-2596430Monitor
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.
HighCVSS 7.5No exploitEPSS 1%dell · powerscale onefsMar 25, 2024
- CVE-2025-5942530Monitor
vLLM vulnerable to timing attack at bearer auth
HighCVSS 7.5No exploitEPSS 1%vllm · vllmOct 7, 2025
- CVE-2023-4680929Monitor
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are
HighCVSS 7.4No exploitEPSS 1%nodejs · nodeSep 7, 2024
- CVE-2025-030629Monitor
Ruby: openssl: ruby marvin attack
HighCVSS 7.4No exploitEPSS 1%red hat · red hat enterprise linux 10Jan 9, 2025
- CVE-2017-262428Monitor
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.
HighCVSS 7.0No exploitEPSS 1%x.org · x serverJul 27, 2018
- CVE-2025-923127Monitor
Timing side-channel in SM2 algorithm on 64 bit ARM
MediumCVSS 6.5No exploitEPSS 2%openssl · opensslSep 30, 2025
- CVE-2026-647826Monitor
PostgreSQL discloses MD5-hashed passwords via covert timing channel
MediumCVSS 6.5No exploitEPSS 1%postgresql · postgresqlMay 14, 2026
- CVE-2018-1084424Monitor
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.
MediumCVSS 5.9No exploitEPSS 4%gnu · gnutlsAug 22, 2018
- CVE-2018-1084524Monitor
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.
MediumCVSS 5.9No exploitEPSS 4%gnu · gnutlsAug 22, 2018
- CVE-2020-2565924Monitor
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
MediumCVSS 5.9No exploitEPSS 2%cryptography.io · cryptographyJan 11, 2021
- CVE-2020-2565724Monitor
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API
MediumCVSS 5.9No exploitEPSS 2%m2crypto project · m2cryptoJan 12, 2021
- CVE-2020-2565823Monitor
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.
MediumCVSS 5.9No exploitEPSS 2%python-rsa project · python-rsaNov 12, 2020
- CVE-2024-223623Monitor
Libgcrypt: vulnerable to marvin attack
MediumCVSS 5.9No exploitEPSS 1%red hat · red hat enterprise linux 9Mar 6, 2024
- CVE-2024-2630623Monitor
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption
MediumCVSS 5.9No exploitEPSS 1%es · iperf3May 14, 2024
- CVE-2023-4909223Monitor
RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels
MediumCVSS 5.9No exploitEPSS 1%rustcrypto · rsaNov 28, 2023
- CVE-2016-705622Monitor
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 priva
MediumCVSS 5.5No exploitEPSS 1%openssl · opensslSep 10, 2018
- CVE-2018-1084622Monitor
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.
MediumCVSS 5.6No exploitEPSS 0%gnu · gnutlsAug 22, 2018