libtom records
4 published records for vendor libtom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read1
- CWE-190 Integer Overflow or Wraparound1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-36328No exploit | Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to elibtom · libtommath · CWE-190 | Critical9.8 | — | 1.3% | Sep 1, 2023 |
37Monitor | CVE-2019-17362No exploit | In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTlibtom · libtomcrypt · CWE-125 | Critical9.1 | — | 3.1% | Oct 8, 2019 |
30Monitor | CVE-2016-6129No exploit | The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message lenglibtom · libtomcrypt · CWE-20 | High7.5 | — | 0.8% | Feb 13, 2017 |
19Monitor | CVE-2018-12437No exploit | LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHlibtom · libtomcrypt · CWE-200 | Medium4.9 | — | 0.5% | Jun 14, 2018 |
- CVE-2023-3632839Monitor
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to e
CriticalCVSS 9.8No exploitEPSS 1%libtom · libtommathSep 1, 2023
- CVE-2019-1736237Monitor
In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UT
CriticalCVSS 9.1No exploitEPSS 3%libtom · libtomcryptOct 8, 2019
- CVE-2016-612930Monitor
The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message leng
HighCVSS 7.5No exploitEPSS 1%libtom · libtomcryptFeb 13, 2017
- CVE-2018-1243719Monitor
LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROH
MediumCVSS 4.9No exploitEPSS 1%libtom · libtomcryptJun 14, 2018