Skip to content
Noroxi

cryptography.io records

11 published records for vendor cryptography.io.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

11 records
  • In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result

    CriticalCVSS 9.1No exploitEPSS 7%

    cryptography.io · cryptographyFeb 7, 2021

  • cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

    HighCVSS 8.2No exploitEPSS 0%

    cryptography.io · cryptographyFeb 10, 2026

  • CVE-2016-9243
    31Monitor

    HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

    HighCVSS 7.5No exploitEPSS 3%

    cryptography.io · cryptographyMar 27, 2017

  • Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659

    HighCVSS 7.5No exploitEPSS 1%

    redhat · ansible automation platformFeb 5, 2024

  • cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

    HighCVSS 7.5No exploitEPSS 1%

    cryptography.io · cryptographyNov 29, 2023

  • cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash over

    HighCVSS 7.5No exploitEPSS 1%

    cryptography.io · cryptographyFeb 21, 2024

  • The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

    HighCVSS 7.5No exploitEPSS 1%

    cryptography.io · cryptographyJul 14, 2023

  • cryptography has a buffer overflow if non-contiguous buffers were passed to APIs

    MediumCVSS 6.9No exploitEPSS 1%

    cryptography.io · cryptographyApr 8, 2026

  • Cipher.update_into can corrupt memory in pyca cryptography

    MediumCVSS 6.5No exploitEPSS 1%

    cryptography.io · cryptographyFeb 7, 2023

  • python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5

    MediumCVSS 5.9No exploitEPSS 2%

    cryptography.io · cryptographyJan 11, 2021

  • cryptography has incomplete DNS name constraint enforcement on peer names

    LowCVSS 1.7No exploitEPSS 0%

    cryptography.io · cryptographyMar 30, 2026