cryptopp records
14 published records for vendor cryptopp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 71.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-203 Observable Discrepancy2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-399 Resource Management Errors1
- CWE-417 Communication Channel Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-28285No exploit | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Critical9.8 | — | 0.5% | May 14, 2024 |
31Monitor | CVE-2016-9939No exploit | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.cryptopp · crypto\+\+ · CWE-20 | High7.5 | — | 4.2% | Jan 30, 2017 |
31Monitor | CVE-2016-7544No exploit | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.microsoft · windows · CWE-399 | High7.5 | — | 2.7% | Jan 30, 2017 |
31Monitor | CVE-2016-3995No exploit | The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.cryptopp · crypto\+\+ · CWE-200 | High7.5 | — | 1.9% | Feb 13, 2017 |
30Monitor | CVE-2022-48570No exploit | Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-787 | High7.5 | — | 1.0% | Aug 22, 2023 |
30Monitor | CVE-2023-50980No exploit | gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data cryptopp · crypto\+\+ | High7.5 | — | 0.8% | Dec 18, 2023 |
30Monitor | CVE-2023-50981No exploit | ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pubcryptopp · crypto\+\+ · CWE-835 | High7.5 | — | 0.8% | Dec 18, 2023 |
24Monitor | CVE-2019-14318No exploit | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-417 | Medium5.9 | — | 2.7% | Jul 30, 2019 |
24Monitor | CVE-2016-7420No exploit | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert callscryptopp · crypto\+\+ · CWE-200 | Medium5.9 | — | 2.3% | Sep 16, 2016 |
23Monitor | CVE-2021-40530No exploit | The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic librariescryptopp · crypto\+\+ · CWE-327 | Medium5.9 | — | 1.2% | Sep 6, 2021 |
23Monitor | CVE-2023-50979No exploit | Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.cryptopp · crypto\+\+ · CWE-203 | Medium5.9 | — | 0.6% | Dec 18, 2023 |
22Monitor | CVE-2021-43398No exploit | Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().cryptopp · crypto\+\+ · CWE-203 | Medium5.3 | — | 2.0% | Nov 4, 2021 |
21Monitor | CVE-2015-2141No exploit | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabcryptopp · crypto\+\+ library · CWE-200 | Medium5.0 | — | 2.9% | Jul 1, 2015 |
21Monitor | CVE-2017-9434No exploit | Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.cryptopp · crypto\+\+ · CWE-125 | Medium5.3 | — | 1.4% | Jun 5, 2017 |
- CVE-2024-2828539Monitor
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
CriticalCVSS 9.8No exploitEPSS 1%May 14, 2024
- CVE-2016-993931Monitor
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.
HighCVSS 7.5No exploitEPSS 4%cryptopp · crypto\+\+Jan 30, 2017
- CVE-2016-754431Monitor
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.
HighCVSS 7.5No exploitEPSS 3%microsoft · windowsJan 30, 2017
- CVE-2016-399531Monitor
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.
HighCVSS 7.5No exploitEPSS 2%cryptopp · crypto\+\+Feb 13, 2017
- CVE-2022-4857030Monitor
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.
HighCVSS 7.5No exploitEPSS 1%cryptopp · crypto\+\+Aug 22, 2023
- CVE-2023-5098030Monitor
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data
HighCVSS 7.5No exploitEPSS 1%cryptopp · crypto\+\+Dec 18, 2023
- CVE-2023-5098130Monitor
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pub
HighCVSS 7.5No exploitEPSS 1%cryptopp · crypto\+\+Dec 18, 2023
- CVE-2019-1431824Monitor
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.
MediumCVSS 5.9No exploitEPSS 3%cryptopp · crypto\+\+Jul 30, 2019
- CVE-2016-742024Monitor
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls
MediumCVSS 5.9No exploitEPSS 2%cryptopp · crypto\+\+Sep 16, 2016
- CVE-2021-4053023Monitor
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries
MediumCVSS 5.9No exploitEPSS 1%cryptopp · crypto\+\+Sep 6, 2021
- CVE-2023-5097923Monitor
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.
MediumCVSS 5.9No exploitEPSS 1%cryptopp · crypto\+\+Dec 18, 2023
- CVE-2021-4339822Monitor
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().
MediumCVSS 5.3No exploitEPSS 2%cryptopp · crypto\+\+Nov 4, 2021
- CVE-2015-214121Monitor
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rab
MediumCVSS 5.0No exploitEPSS 3%cryptopp · crypto\+\+ libraryJul 1, 2015
- CVE-2017-943421Monitor
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
MediumCVSS 5.3No exploitEPSS 1%cryptopp · crypto\+\+Jun 5, 2017