Записи gpg4win
7 опубликованных записей вендора gpg4win.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-121 Stack-based Buffer Overflow2
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')1
- CWE-190 Integer Overflow or Wraparound1
- CWE-476 NULL Pointer Dereference1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2006-6235Эксплойта нет | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute argnu · privacy guard | Критическая10,0 | — | 5,9 % | 7 дек. 2006 г. |
40В плане | CVE-2026-24881Эксплойта нет | In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffegnupg · gnupg · CWE-121 | Критическая9,8 | — | 1,8 % | 27 янв. 2026 г. |
39Наблюдать | CVE-2022-3515Эксплойта нет | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser.gnupg · libksba · CWE-190 | Критическая9,8 | — | 1,6 % | 12 янв. 2023 г. |
31Наблюдать | CVE-2020-25125Эксплойта нет | GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim ignupg · gnupg · CWE-120 | Высокая7,8 | — | 1,3 % | 3 сент. 2020 г. |
31Наблюдать | CVE-2026-24882Эксплойта нет | In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and Egnupg · gnupg · CWE-121 | Высокая7,8 | — | 0,4 % | 27 янв. 2026 г. |
22Наблюдать | CVE-2026-24883Эксплойта нет | In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leadingnupg · gnupg · CWE-476 | Средняя5,5 | — | 0,5 % | 27 янв. 2026 г. |
17Наблюдать | CVE-2009-3805Proof of concept | gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a lgpg4win · gpg4win | Средняя4,3 | — | 1,4 % | 27 окт. 2009 г. |
- CVE-2006-623542В плане
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute ar
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %gnu · privacy guard7 дек. 2006 г.
- CVE-2026-2488140В плане
In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffe
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnupg · gnupg27 янв. 2026 г.
- CVE-2022-351539Наблюдать
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gnupg · libksba12 янв. 2023 г.
- CVE-2020-2512531Наблюдать
GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim i
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %gnupg · gnupg3 сент. 2020 г.
- CVE-2026-2488231Наблюдать
In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and E
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %gnupg · gnupg27 янв. 2026 г.
- CVE-2026-2488322Наблюдать
In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leadin
СредняяCVSS 5,5Эксплойта нетEPSS 0 %gnupg · gnupg27 янв. 2026 г.
- CVE-2009-380517Наблюдать
gpg2.exe in Gpg4win 2.0.1, as used in KDE Kleopatra 2.0.11, allows remote attackers to cause a denial of service (application crash) via a l
СредняяCVSS 4,3Proof of conceptEPSS 1 %gpg4win · gpg4win27 окт. 2009 г.