Записи openpgpjs
5 опубликованных записей вендора openpgpjs.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-310 Cryptographic Issues1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
31Наблюдать | CVE-2015-8013Эксплойта нет | s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass aopenpgpjs · openpgpjs · CWE-310 | Высокая7,5 | — | 3,9 % | 25 июл. 2017 г. |
31Наблюдать | CVE-2019-9153Proof of concept | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatopenpgpjs · openpgpjs · CWE-347 | Высокая7,5 | — | 2,0 % | 22 авг. 2019 г. |
30Наблюдать | CVE-2019-9154Эксплойта нет | Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.openpgpjs · openpgpjs · CWE-347 | Высокая7,5 | — | 1,6 % | 22 авг. 2019 г. |
23Наблюдать | CVE-2019-9155Эксплойта нет | A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptioopenpgpjs · openpgpjs · CWE-327 | Средняя5,9 | — | 1,5 % | 22 авг. 2019 г. |
17Наблюдать | CVE-2023-41037Эксплойта нет | Cleartext Signed Message Signature Spoofing in openpgpjsopenpgpjs · openpgpjs · CWE-347 | Средняя4,3 | — | 0,4 % | 29 авг. 2023 г. |
- CVE-2015-801331Наблюдать
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %openpgpjs · openpgpjs25 июл. 2017 г.
- CVE-2019-915331Наблюдать
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signat
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %openpgpjs · openpgpjs22 авг. 2019 г.
- CVE-2019-915430Наблюдать
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to pass off unsigned data as signed.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %openpgpjs · openpgpjs22 авг. 2019 г.
- CVE-2019-915523Наблюдать
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryptio
СредняяCVSS 5,9Эксплойта нетEPSS 1 %openpgpjs · openpgpjs22 авг. 2019 г.
- CVE-2023-4103717Наблюдать
Cleartext Signed Message Signature Spoofing in openpgpjs
СредняяCVSS 4,3Эксплойта нетEPSS 0 %openpgpjs · openpgpjs29 авг. 2023 г.