Записи cryptopp
14 опубликованных записей вендора cryptopp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 71,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-203 Observable Discrepancy2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-399 Resource Management Errors1
- CWE-417 Communication Channel Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
14 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-28285Эксплойта нет | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Критическая9,8 | — | 0,5 % | 14 мая 2024 г. |
31Наблюдать | CVE-2016-9939Эксплойта нет | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.cryptopp · crypto\+\+ · CWE-20 | Высокая7,5 | — | 4,2 % | 30 янв. 2017 г. |
31Наблюдать | CVE-2016-7544Эксплойта нет | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.microsoft · windows · CWE-399 | Высокая7,5 | — | 2,7 % | 30 янв. 2017 г. |
31Наблюдать | CVE-2016-3995Эксплойта нет | The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.cryptopp · crypto\+\+ · CWE-200 | Высокая7,5 | — | 1,9 % | 13 февр. 2017 г. |
30Наблюдать | CVE-2022-48570Эксплойта нет | Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-787 | Высокая7,5 | — | 1,0 % | 22 авг. 2023 г. |
30Наблюдать | CVE-2023-50980Эксплойта нет | gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data cryptopp · crypto\+\+ | Высокая7,5 | — | 0,8 % | 18 дек. 2023 г. |
30Наблюдать | CVE-2023-50981Эксплойта нет | ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pubcryptopp · crypto\+\+ · CWE-835 | Высокая7,5 | — | 0,8 % | 18 дек. 2023 г. |
24Наблюдать | CVE-2019-14318Эксплойта нет | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-417 | Средняя5,9 | — | 2,7 % | 30 июл. 2019 г. |
24Наблюдать | CVE-2016-7420Эксплойта нет | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert callscryptopp · crypto\+\+ · CWE-200 | Средняя5,9 | — | 2,0 % | 16 сент. 2016 г. |
23Наблюдать | CVE-2021-40530Эксплойта нет | The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic librariescryptopp · crypto\+\+ · CWE-327 | Средняя5,9 | — | 1,2 % | 6 сент. 2021 г. |
23Наблюдать | CVE-2023-50979Эксплойта нет | Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.cryptopp · crypto\+\+ · CWE-203 | Средняя5,9 | — | 0,6 % | 18 дек. 2023 г. |
22Наблюдать | CVE-2021-43398Эксплойта нет | Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().cryptopp · crypto\+\+ · CWE-203 | Средняя5,3 | — | 2,0 % | 4 нояб. 2021 г. |
21Наблюдать | CVE-2015-2141Эксплойта нет | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabcryptopp · crypto\+\+ library · CWE-200 | Средняя5,0 | — | 2,9 % | 1 июл. 2015 г. |
21Наблюдать | CVE-2017-9434Эксплойта нет | Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.cryptopp · crypto\+\+ · CWE-125 | Средняя5,3 | — | 1,4 % | 5 июн. 2017 г. |
- CVE-2024-2828539Наблюдать
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %14 мая 2024 г.
- CVE-2016-993931Наблюдать
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %cryptopp · crypto\+\+30 янв. 2017 г.
- CVE-2016-754431Наблюдать
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %microsoft · windows30 янв. 2017 г.
- CVE-2016-399531Наблюдать
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %cryptopp · crypto\+\+13 февр. 2017 г.
- CVE-2022-4857030Наблюдать
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptopp · crypto\+\+22 авг. 2023 г.
- CVE-2023-5098030Наблюдать
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptopp · crypto\+\+18 дек. 2023 г.
- CVE-2023-5098130Наблюдать
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pub
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cryptopp · crypto\+\+18 дек. 2023 г.
- CVE-2019-1431824Наблюдать
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.
СредняяCVSS 5,9Эксплойта нетEPSS 3 %cryptopp · crypto\+\+30 июл. 2019 г.
- CVE-2016-742024Наблюдать
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls
СредняяCVSS 5,9Эксплойта нетEPSS 2 %cryptopp · crypto\+\+16 сент. 2016 г.
- CVE-2021-4053023Наблюдать
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries
СредняяCVSS 5,9Эксплойта нетEPSS 1 %cryptopp · crypto\+\+6 сент. 2021 г.
- CVE-2023-5097923Наблюдать
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %cryptopp · crypto\+\+18 дек. 2023 г.
- CVE-2021-4339822Наблюдать
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().
СредняяCVSS 5,3Эксплойта нетEPSS 2 %cryptopp · crypto\+\+4 нояб. 2021 г.
- CVE-2015-214121Наблюдать
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rab
СредняяCVSS 5,0Эксплойта нетEPSS 3 %cryptopp · crypto\+\+ library1 июл. 2015 г.
- CVE-2017-943421Наблюдать
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %cryptopp · crypto\+\+5 июн. 2017 г.