Записи latchset
6 опубликованных записей вендора latchset.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption2
- CWE-1300 Improper Protection of Physical Side Channels1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification)1
- CWE-770 Allocation of Resources Without Limits or Throttling1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2023-6258Эксплойта нет | Pkcs11-provider: side-channel proofing pkcs#1 1.5 pathslatchset · pkcs11-provider · CWE-1300 | Высокая8,1 | — | 0,6 % | 30 янв. 2024 г. |
30Наблюдать | CVE-2023-50967Эксплойта нет | latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.latchset · jose · CWE-400 | Высокая7,5 | — | 1,4 % | 20 мар. 2024 г. |
27Наблюдать | CVE-2024-28102Эксплойта нет | JWCrypto vulnerable to JWT bomb Attack in `deserialize` functionlatchset · jwcrypto · CWE-770 | Средняя6,8 | — | 1,0 % | 20 мар. 2024 г. |
22Наблюдать | CVE-2016-6298Эксплойта нет | The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, wlatchset · jwcrypto · CWE-200 | Средняя5,3 | — | 2,2 % | 1 сент. 2016 г. |
21Наблюдать | CVE-2023-6681Эксплойта нет | Jwcrypto: denail of service via specifically crafted jwelatchset · jwcrypto · CWE-400 | Средняя5,3 | — | 0,9 % | 12 февр. 2024 г. |
21Наблюдать | CVE-2026-39373Эксплойта нет | JWCrypto: JWE ZIP decompression bomblatchset · jwcrypto · CWE-409 | Средняя5,3 | — | 0,4 % | 7 апр. 2026 г. |
- CVE-2023-625832Наблюдать
Pkcs11-provider: side-channel proofing pkcs#1 1.5 paths
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %latchset · pkcs11-provider30 янв. 2024 г.
- CVE-2023-5096730Наблюдать
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %latchset · jose20 мар. 2024 г.
- CVE-2024-2810227Наблюдать
JWCrypto vulnerable to JWT bomb Attack in `deserialize` function
СредняяCVSS 6,8Эксплойта нетEPSS 1 %latchset · jwcrypto20 мар. 2024 г.
- CVE-2016-629822Наблюдать
The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, w
СредняяCVSS 5,3Эксплойта нетEPSS 2 %latchset · jwcrypto1 сент. 2016 г.
- CVE-2023-668121Наблюдать
Jwcrypto: denail of service via specifically crafted jwe
СредняяCVSS 5,3Эксплойта нетEPSS 1 %latchset · jwcrypto12 февр. 2024 г.
- CVE-2026-3937321Наблюдать
JWCrypto: JWE ZIP decompression bomb
СредняяCVSS 5,3Эксплойта нетEPSS 0 %latchset · jwcrypto7 апр. 2026 г.