Skip to content
Noroxi

cryptopp records

14 published records for vendor cryptopp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
71.4%
Median publish → KEV
No record has entered KEV

All records

14 records
  • A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re

    CriticalCVSS 9.8No exploitEPSS 1%

    May 14, 2024

  • CVE-2016-9939
    31Monitor

    Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.

    HighCVSS 7.5No exploitEPSS 4%

    cryptopp · crypto\+\+Jan 30, 2017

  • CVE-2016-7544
    31Monitor

    Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.

    HighCVSS 7.5No exploitEPSS 3%

    microsoft · windowsJan 30, 2017

  • CVE-2016-3995
    31Monitor

    The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.

    HighCVSS 7.5No exploitEPSS 2%

    cryptopp · crypto\+\+Feb 13, 2017

  • Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.

    HighCVSS 7.5No exploitEPSS 1%

    cryptopp · crypto\+\+Aug 22, 2023

  • gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data

    HighCVSS 7.5No exploitEPSS 1%

    cryptopp · crypto\+\+Dec 18, 2023

  • ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pub

    HighCVSS 7.5No exploitEPSS 1%

    cryptopp · crypto\+\+Dec 18, 2023

  • Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.

    MediumCVSS 5.9No exploitEPSS 3%

    cryptopp · crypto\+\+Jul 30, 2019

  • CVE-2016-7420
    24Monitor

    Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls

    MediumCVSS 5.9No exploitEPSS 2%

    cryptopp · crypto\+\+Sep 16, 2016

  • The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries

    MediumCVSS 5.9No exploitEPSS 1%

    cryptopp · crypto\+\+Sep 6, 2021

  • Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.

    MediumCVSS 5.9No exploitEPSS 1%

    cryptopp · crypto\+\+Dec 18, 2023

  • Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().

    MediumCVSS 5.3No exploitEPSS 2%

    cryptopp · crypto\+\+Nov 4, 2021

  • CVE-2015-2141
    21Monitor

    The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rab

    MediumCVSS 5.0No exploitEPSS 3%

    cryptopp · crypto\+\+ libraryJul 1, 2015

  • CVE-2017-9434
    21Monitor

    Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.

    MediumCVSS 5.3No exploitEPSS 1%

    cryptopp · crypto\+\+Jun 5, 2017