Перейти к содержимому
Noroxi

CWE-385 · 35 записей

Covert Timing Channel

CVE этого класса

35 записей

  • CVE-2020-29506
    39Наблюдать

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable T

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · bsafe crypto-c-micro-edition11 июл. 2022 г.

  • CVE-2020-35166
    39Наблюдать

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · bsafe crypto-c-micro-edition11 июл. 2022 г.

  • CVE-2026-5598
    35Наблюдать

    Non-constant time comparisons risk private key leakage in FrodoKEM.

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    legion of the bouncy castle inc. · bc-java15 апр. 2026 г.

  • CVE-2020-35164
    32Наблюдать

    Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    dell · bsafe crypto-c-micro-edition11 июл. 2022 г.

  • GHSA-hvh4-5qr6-3v7r
    32Наблюдать

    Observable Timing Discrepancy in pypqc

    ВысокаяCVSS 8,2Эксплойта нет

    PyPI · pypqc5 июн. 2024 г.

  • CVE-2023-3640
    31Наблюдать

    Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the p

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    linux · linux kernel24 июл. 2023 г.

  • CVE-2019-3732
    30Наблюдать

    RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dell · bsafe crypto-c-micro-edition30 сент. 2019 г.

  • CVE-2022-24409
    30Наблюдать

    Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dell · bsafe ssl-j23 февр. 2022 г.

  • CVE-2024-25964
    30Наблюдать

    Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    dell · powerscale onefs25 мар. 2024 г.

  • CVE-2025-59425
    30Наблюдать

    vLLM vulnerable to timing attack at bearer auth

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    vllm · vllm7 окт. 2025 г.

  • CVE-2023-46809
    29Наблюдать

    Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    nodejs · node7 сент. 2024 г.

  • CVE-2025-0306
    29Наблюдать

    Ruby: openssl: ruby marvin attack

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    red hat · red hat enterprise linux 109 янв. 2025 г.

  • CVE-2017-2624
    28Наблюдать

    It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.

    ВысокаяCVSS 7,0Эксплойта нетEPSS 1 %

    x.org · x server27 июл. 2018 г.

  • CVE-2025-9231
    27Наблюдать

    Timing side-channel in SM2 algorithm on 64 bit ARM

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    openssl · openssl30 сент. 2025 г.

  • CVE-2026-6478
    26Наблюдать

    PostgreSQL discloses MD5-hashed passwords via covert timing channel

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    postgresql · postgresql14 мая 2026 г.

  • CVE-2018-10844
    24Наблюдать

    It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.

    СредняяCVSS 5,9Эксплойта нетEPSS 4 %

    gnu · gnutls22 авг. 2018 г.

  • CVE-2018-10845
    24Наблюдать

    It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.

    СредняяCVSS 5,9Эксплойта нетEPSS 4 %

    gnu · gnutls22 авг. 2018 г.

  • CVE-2020-25659
    24Наблюдать

    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5

    СредняяCVSS 5,9Эксплойта нетEPSS 2 %

    cryptography.io · cryptography11 янв. 2021 г.

  • CVE-2020-25657
    24Наблюдать

    A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API

    СредняяCVSS 5,9Эксплойта нетEPSS 2 %

    m2crypto project · m2crypto12 янв. 2021 г.

  • CVE-2020-25658
    23Наблюдать

    It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.

    СредняяCVSS 5,9Эксплойта нетEPSS 2 %

    python-rsa project · python-rsa12 нояб. 2020 г.

  • CVE-2024-2236
    23Наблюдать

    Libgcrypt: vulnerable to marvin attack

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    red hat · red hat enterprise linux 96 мар. 2024 г.

  • CVE-2024-26306
    23Наблюдать

    iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    es · iperf314 мая 2024 г.

  • CVE-2023-49092
    23Наблюдать

    RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels

    СредняяCVSS 5,9Эксплойта нетEPSS 1 %

    rustcrypto · rsa28 нояб. 2023 г.

  • CVE-2016-7056
    22Наблюдать

    A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 priva

    СредняяCVSS 5,5Эксплойта нетEPSS 1 %

    openssl · openssl10 сент. 2018 г.

  • CVE-2018-10846
    22Наблюдать

    A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.

    СредняяCVSS 5,6Эксплойта нетEPSS 0 %

    gnu · gnutls22 авг. 2018 г.

Все классы уязвимостей