openpgpjs records
5 published records for vendor openpgpjs.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-310 Cryptographic Issues1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2015-8013No exploit | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass aopenpgpjs · openpgpjs · CWE-310 | High7.5 | — | 3.9% | Jul 25, 2017 |
31Monitor | CVE-2019-9153Proof of concept | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatopenpgpjs · openpgpjs · CWE-347 | High7.5 | — | 2.0% | Aug 22, 2019 |
30Monitor | CVE-2019-9154No exploit | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.openpgpjs · openpgpjs · CWE-347 | High7.5 | — | 1.6% | Aug 22, 2019 |
23Monitor | CVE-2019-9155No exploit | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptioopenpgpjs · openpgpjs · CWE-327 | Medium5.9 | — | 1.5% | Aug 22, 2019 |
17Monitor | CVE-2023-41037No exploit | Cleartext Signed Message Signature Spoofing in openpgpjsopenpgpjs · openpgpjs · CWE-347 | Medium4.3 | — | 0.4% | Aug 29, 2023 |
- CVE-2015-801331Monitor
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass a
HighCVSS 7.5No exploitEPSS 4%openpgpjs · openpgpjsJul 25, 2017
- CVE-2019-915331Monitor
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signat
HighCVSS 7.5Proof of conceptEPSS 2%openpgpjs · openpgpjsAug 22, 2019
- CVE-2019-915430Monitor
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
HighCVSS 7.5No exploitEPSS 2%openpgpjs · openpgpjsAug 22, 2019
- CVE-2019-915523Monitor
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptio
MediumCVSS 5.9No exploitEPSS 1%openpgpjs · openpgpjsAug 22, 2019
- CVE-2023-4103717Monitor
Cleartext Signed Message Signature Spoofing in openpgpjs
MediumCVSS 4.3No exploitEPSS 0%openpgpjs · openpgpjsAug 29, 2023