Записи cryptography.io
11 опубликованных записей вендора cryptography.io.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference2
- CWE-295 Improper Certificate Validation2
- CWE-203 Observable Discrepancy1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-385 Covert Timing Channel1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2020-36242Эксплойта нет | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could resultcryptography.io · cryptography · CWE-190 | Критическая9,1 | — | 6,7 % | 7 февр. 2021 г. |
32Наблюдать | CVE-2026-26007Эксплойта нет | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curvescryptography.io · cryptography · CWE-345 | Высокая8,2 | — | 0,3 % | 10 февр. 2026 г. |
31Наблюдать | CVE-2016-9243Эксплойта нет | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.cryptography.io · cryptography | Высокая7,5 | — | 3,5 % | 27 мар. 2017 г. |
30Наблюдать | CVE-2023-50782Эксплойта нет | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659redhat · ansible automation platform · CWE-203 | Высокая7,5 | — | 1,1 % | 5 февр. 2024 г. |
30Наблюдать | CVE-2023-49083Эксплойта нет | cryptography vulnerable to NULL-dereference when loading PKCS7 certificatescryptography.io · cryptography · CWE-476 | Высокая7,5 | — | 1,0 % | 29 нояб. 2023 г. |
30Наблюдать | CVE-2024-26130Эксплойта нет | cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash overcryptography.io · cryptography · CWE-476 | Высокая7,5 | — | 0,8 % | 21 февр. 2024 г. |
30Наблюдать | CVE-2023-38325Эксплойта нет | The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.cryptography.io · cryptography · CWE-295 | Высокая7,5 | — | 0,7 % | 14 июл. 2023 г. |
27Наблюдать | CVE-2026-39892Эксплойта нет | cryptography has a buffer overflow if non-contiguous buffers were passed to APIscryptography.io · cryptography · CWE-119 | Средняя6,9 | — | 0,8 % | 8 апр. 2026 г. |
26Наблюдать | CVE-2023-23931Эксплойта нет | Cipher.update_into can corrupt memory in pyca cryptographycryptography.io · cryptography · CWE-754 | Средняя6,5 | — | 1,3 % | 7 февр. 2023 г. |
24Наблюдать | CVE-2020-25659Эксплойта нет | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Средняя5,9 | — | 2,4 % | 11 янв. 2021 г. |
6Наблюдать | CVE-2026-34073Эксплойта нет | cryptography has incomplete DNS name constraint enforcement on peer namescryptography.io · cryptography · CWE-295 | Низкая1,7 | — | 0,2 % | 30 мар. 2026 г. |
- CVE-2020-3624238Наблюдать
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result
КритическаяCVSS 9,1Эксплойта нетEPSS 7 %cryptography.io · cryptography7 февр. 2021 г.
- CVE-2026-2600732Наблюдать
cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %cryptography.io · cryptography10 февр. 2026 г.
- CVE-2016-924331Наблюдать
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %cryptography.io · cryptography27 мар. 2017 г.
- CVE-2023-5078230Наблюдать
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %redhat · ansible automation platform5 февр. 2024 г.
- CVE-2023-4908330Наблюдать
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptography.io · cryptography29 нояб. 2023 г.
- CVE-2024-2613030Наблюдать
cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash over
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptography.io · cryptography21 февр. 2024 г.
- CVE-2023-3832530Наблюдать
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptography.io · cryptography14 июл. 2023 г.
- CVE-2026-3989227Наблюдать
cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
СредняяCVSS 6,9Эксплойта нетEPSS 1 %cryptography.io · cryptography8 апр. 2026 г.
- CVE-2023-2393126Наблюдать
Cipher.update_into can corrupt memory in pyca cryptography
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cryptography.io · cryptography7 февр. 2023 г.
- CVE-2020-2565924Наблюдать
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
СредняяCVSS 5,9Эксплойта нетEPSS 2 %cryptography.io · cryptography11 янв. 2021 г.
- CVE-2026-340736Наблюдать
cryptography has incomplete DNS name constraint enforcement on peer names
НизкаяCVSS 1,7Эксплойта нетEPSS 0 %cryptography.io · cryptography30 мар. 2026 г.