latchset records
6 published records for vendor latchset.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption2
- CWE-1300 Improper Protection of Physical Side Channels1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2023-6258No exploit | Pkcs11-provider: side-channel proofing pkcs#1 1.5 pathslatchset · pkcs11-provider · CWE-1300 | High8.1 | — | 0.6% | Jan 30, 2024 |
30Monitor | CVE-2023-50967No exploit | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.latchset · jose · CWE-400 | High7.5 | — | 1.4% | Mar 20, 2024 |
27Monitor | CVE-2024-28102No exploit | JWCrypto vulnerable to JWT bomb Attack in `deserialize` functionlatchset · jwcrypto · CWE-770 | Medium6.8 | — | 1.0% | Mar 20, 2024 |
22Monitor | CVE-2016-6298No exploit | The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, wlatchset · jwcrypto · CWE-200 | Medium5.3 | — | 2.2% | Sep 1, 2016 |
21Monitor | CVE-2023-6681No exploit | Jwcrypto: denail of service via specifically crafted jwelatchset · jwcrypto · CWE-400 | Medium5.3 | — | 0.9% | Feb 12, 2024 |
21Monitor | CVE-2026-39373No exploit | JWCrypto: JWE ZIP decompression bomblatchset · jwcrypto · CWE-409 | Medium5.3 | — | 0.4% | Apr 7, 2026 |
- CVE-2023-625832Monitor
Pkcs11-provider: side-channel proofing pkcs#1 1.5 paths
HighCVSS 8.1No exploitEPSS 1%latchset · pkcs11-providerJan 30, 2024
- CVE-2023-5096730Monitor
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
HighCVSS 7.5No exploitEPSS 1%latchset · joseMar 20, 2024
- CVE-2024-2810227Monitor
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
MediumCVSS 6.8No exploitEPSS 1%latchset · jwcryptoMar 20, 2024
- CVE-2016-629822Monitor
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, w
MediumCVSS 5.3No exploitEPSS 2%latchset · jwcryptoSep 1, 2016
- CVE-2023-668121Monitor
Jwcrypto: denail of service via specifically crafted jwe
MediumCVSS 5.3No exploitEPSS 1%latchset · jwcryptoFeb 12, 2024
- CVE-2026-3937321Monitor
JWCrypto: JWE ZIP decompression bomb
MediumCVSS 5.3No exploitEPSS 0%latchset · jwcryptoApr 7, 2026