CWE-385 · 35 записей
Covert Timing Channel
CVE этого класса
35 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-29506Эксплойта нет | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Tdell · bsafe crypto-c-micro-edition · CWE-385 | Критическая9,8 | — | 1,2 % | 11 июл. 2022 г. |
39Наблюдать | CVE-2020-35166Эксплойта нет | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | Критическая9,8 | — | 0,7 % | 11 июл. 2022 г. |
35Наблюдать | CVE-2026-5598Эксплойта нет | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Высокая8,9 | — | 1,0 % | 15 апр. 2026 г. |
32Наблюдать | CVE-2020-35164Эксплойта нет | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | Высокая8,1 | — | 0,8 % | 11 июл. 2022 г. |
32Наблюдать | GHSA-hvh4-5qr6-3v7rЭксплойта нет | Observable Timing Discrepancy in pypqcPyPI · pypqc · CWE-385 | Высокая8,2 | — | — | 5 июн. 2024 г. |
31Наблюдать | CVE-2023-3640Proof of concept | Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the plinux · linux kernel · CWE-385 | Высокая7,8 | — | 0,8 % | 24 июл. 2023 г. |
30Наблюдать | CVE-2019-3732Эксплойта нет | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suitedell · bsafe crypto-c-micro-edition · CWE-385 | Высокая7,5 | — | 1,4 % | 30 сент. 2019 г. |
30Наблюдать | CVE-2022-24409Эксплойта нет | Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the adell · bsafe ssl-j · CWE-385 | Высокая7,5 | — | 1,0 % | 23 февр. 2022 г. |
30Наблюдать | CVE-2024-25964Эксплойта нет | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.dell · powerscale onefs · CWE-385 | Высокая7,5 | — | 0,7 % | 25 мар. 2024 г. |
30Наблюдать | CVE-2025-59425Эксплойта нет | vLLM vulnerable to timing attack at bearer authvllm · vllm · CWE-385 | Высокая7,5 | — | 0,6 % | 7 окт. 2025 г. |
29Наблюдать | CVE-2023-46809Эксплойта нет | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched arenodejs · node · CWE-385 | Высокая7,4 | — | 1,3 % | 7 сент. 2024 г. |
29Наблюдать | CVE-2025-0306Эксплойта нет | Ruby: openssl: ruby marvin attackred hat · red hat enterprise linux 10 · CWE-385 | Высокая7,4 | — | 0,6 % | 9 янв. 2025 г. |
28Наблюдать | CVE-2017-2624Эксплойта нет | It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.x.org · x server · CWE-385 | Высокая7,0 | — | 0,7 % | 27 июл. 2018 г. |
27Наблюдать | CVE-2025-9231Эксплойта нет | Timing side-channel in SM2 algorithm on 64 bit ARMopenssl · openssl · CWE-385 | Средняя6,5 | — | 2,2 % | 30 сент. 2025 г. |
26Наблюдать | CVE-2026-6478Эксплойта нет | PostgreSQL discloses MD5-hashed passwords via covert timing channelpostgresql · postgresql · CWE-385 | Средняя6,5 | — | 0,6 % | 14 мая 2026 г. |
24Наблюдать | CVE-2018-10844Эксплойта нет | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Средняя5,9 | — | 3,6 % | 22 авг. 2018 г. |
24Наблюдать | CVE-2018-10845Эксплойта нет | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Средняя5,9 | — | 3,6 % | 22 авг. 2018 г. |
24Наблюдать | CVE-2020-25659Эксплойта нет | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Средняя5,9 | — | 2,4 % | 11 янв. 2021 г. |
24Наблюдать | CVE-2020-25657Эксплойта нет | A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API m2crypto project · m2crypto · CWE-385 | Средняя5,9 | — | 1,7 % | 12 янв. 2021 г. |
23Наблюдать | CVE-2020-25658Эксплойта нет | It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.python-rsa project · python-rsa · CWE-385 | Средняя5,9 | — | 1,7 % | 12 нояб. 2020 г. |
23Наблюдать | CVE-2024-2236Эксплойта нет | Libgcrypt: vulnerable to marvin attackred hat · red hat enterprise linux 9 · CWE-385 | Средняя5,9 | — | 1,1 % | 6 мар. 2024 г. |
23Наблюдать | CVE-2024-26306Эксплойта нет | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption es · iperf3 · CWE-385 | Средняя5,9 | — | 1,1 % | 14 мая 2024 г. |
23Наблюдать | CVE-2023-49092Эксплойта нет | RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannelsrustcrypto · rsa · CWE-385 | Средняя5,9 | — | 0,6 % | 28 нояб. 2023 г. |
22Наблюдать | CVE-2016-7056Эксплойта нет | A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 privaopenssl · openssl · CWE-385 | Средняя5,5 | — | 0,6 % | 10 сент. 2018 г. |
22Наблюдать | CVE-2018-10846Эксплойта нет | A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.gnu · gnutls · CWE-385 | Средняя5,6 | — | 0,4 % | 22 авг. 2018 г. |
- CVE-2020-2950639Наблюдать
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable T
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · bsafe crypto-c-micro-edition11 июл. 2022 г.
- CVE-2020-3516639Наблюдать
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dell · bsafe crypto-c-micro-edition11 июл. 2022 г.
- CVE-2026-559835Наблюдать
Non-constant time comparisons risk private key leakage in FrodoKEM.
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %legion of the bouncy castle inc. · bc-java15 апр. 2026 г.
- CVE-2020-3516432Наблюдать
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %dell · bsafe crypto-c-micro-edition11 июл. 2022 г.
- GHSA-hvh4-5qr6-3v7r32Наблюдать
Observable Timing Discrepancy in pypqc
ВысокаяCVSS 8,2Эксплойта нетPyPI · pypqc5 июн. 2024 г.
- CVE-2023-364031Наблюдать
Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the p
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %linux · linux kernel24 июл. 2023 г.
- CVE-2019-373230Наблюдать
RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · bsafe crypto-c-micro-edition30 сент. 2019 г.
- CVE-2022-2440930Наблюдать
Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the a
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · bsafe ssl-j23 февр. 2022 г.
- CVE-2024-2596430Наблюдать
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dell · powerscale onefs25 мар. 2024 г.
- CVE-2025-5942530Наблюдать
vLLM vulnerable to timing attack at bearer auth
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %vllm · vllm7 окт. 2025 г.
- CVE-2023-4680929Наблюдать
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %nodejs · node7 сент. 2024 г.
- CVE-2025-030629Наблюдать
Ruby: openssl: ruby marvin attack
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 109 янв. 2025 г.
- CVE-2017-262428Наблюдать
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.
ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %x.org · x server27 июл. 2018 г.
- CVE-2025-923127Наблюдать
Timing side-channel in SM2 algorithm on 64 bit ARM
СредняяCVSS 6,5Эксплойта нетEPSS 2 %openssl · openssl30 сент. 2025 г.
- CVE-2026-647826Наблюдать
PostgreSQL discloses MD5-hashed passwords via covert timing channel
СредняяCVSS 6,5Эксплойта нетEPSS 1 %postgresql · postgresql14 мая 2026 г.
- CVE-2018-1084424Наблюдать
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.
СредняяCVSS 5,9Эксплойта нетEPSS 4 %gnu · gnutls22 авг. 2018 г.
- CVE-2018-1084524Наблюдать
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.
СредняяCVSS 5,9Эксплойта нетEPSS 4 %gnu · gnutls22 авг. 2018 г.
- CVE-2020-2565924Наблюдать
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
СредняяCVSS 5,9Эксплойта нетEPSS 2 %cryptography.io · cryptography11 янв. 2021 г.
- CVE-2020-2565724Наблюдать
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API
СредняяCVSS 5,9Эксплойта нетEPSS 2 %m2crypto project · m2crypto12 янв. 2021 г.
- CVE-2020-2565823Наблюдать
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.
СредняяCVSS 5,9Эксплойта нетEPSS 2 %python-rsa project · python-rsa12 нояб. 2020 г.
- CVE-2024-223623Наблюдать
Libgcrypt: vulnerable to marvin attack
СредняяCVSS 5,9Эксплойта нетEPSS 1 %red hat · red hat enterprise linux 96 мар. 2024 г.
- CVE-2024-2630623Наблюдать
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption
СредняяCVSS 5,9Эксплойта нетEPSS 1 %es · iperf314 мая 2024 г.
- CVE-2023-4909223Наблюдать
RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels
СредняяCVSS 5,9Эксплойта нетEPSS 1 %rustcrypto · rsa28 нояб. 2023 г.
- CVE-2016-705622Наблюдать
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 priva
СредняяCVSS 5,5Эксплойта нетEPSS 1 %openssl · openssl10 сент. 2018 г.
- CVE-2018-1084622Наблюдать
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.
СредняяCVSS 5,6Эксплойта нетEPSS 0 %gnu · gnutls22 авг. 2018 г.