Skip to content
Noroxi

openpgpjs records

5 published records for vendor openpgpjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 17
  2. 19
  3. 23

Bar: total · dark part: CISA KEV.

All records

5 records
  • CVE-2015-8013
    31Monitor

    s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass a

    HighCVSS 7.5No exploitEPSS 4%

    openpgpjs · openpgpjsJul 25, 2017

  • CVE-2019-9153
    31Monitor

    Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signat

    HighCVSS 7.5Proof of conceptEPSS 2%

    openpgpjs · openpgpjsAug 22, 2019

  • CVE-2019-9154
    30Monitor

    Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.

    HighCVSS 7.5No exploitEPSS 2%

    openpgpjs · openpgpjsAug 22, 2019

  • CVE-2019-9155
    23Monitor

    A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptio

    MediumCVSS 5.9No exploitEPSS 1%

    openpgpjs · openpgpjsAug 22, 2019

  • Cleartext Signed Message Signature Spoofing in openpgpjs

    MediumCVSS 4.3No exploitEPSS 0%

    openpgpjs · openpgpjsAug 29, 2023