CWE-385 · 35 kayıt
Covert Timing Channel
Bu sınıftaki CVE’ler
35 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-29506İstismar yok | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Tdell · bsafe crypto-c-micro-edition · CWE-385 | Kritik9,8 | — | %1,2 | 11 Tem 2022 |
39İzleyin | CVE-2020-35166İstismar yok | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | Kritik9,8 | — | %0,7 | 11 Tem 2022 |
35İzleyin | CVE-2026-5598İstismar yok | Non-constant time comparisons risk private key leakage in FrodoKEM.legion of the bouncy castle inc. · bc-java · CWE-385 | Yüksek8,9 | — | %1,0 | 15 Nis 2026 |
32İzleyin | CVE-2020-35164İstismar yok | Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timdell · bsafe crypto-c-micro-edition · CWE-385 | Yüksek8,1 | — | %0,8 | 11 Tem 2022 |
32İzleyin | GHSA-hvh4-5qr6-3v7rİstismar yok | Observable Timing Discrepancy in pypqcPyPI · pypqc · CWE-385 | Yüksek8,2 | — | — | 5 Haz 2024 |
31İzleyin | CVE-2023-3640Kavram kanıtı | Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the plinux · linux kernel · CWE-385 | Yüksek7,8 | — | %0,8 | 24 Tem 2023 |
30İzleyin | CVE-2019-3732İstismar yok | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suitedell · bsafe crypto-c-micro-edition · CWE-385 | Yüksek7,5 | — | %1,4 | 30 Eyl 2019 |
30İzleyin | CVE-2022-24409İstismar yok | Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the adell · bsafe ssl-j · CWE-385 | Yüksek7,5 | — | %1,0 | 23 Şub 2022 |
30İzleyin | CVE-2024-25964İstismar yok | Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.dell · powerscale onefs · CWE-385 | Yüksek7,5 | — | %0,7 | 25 Mar 2024 |
30İzleyin | CVE-2025-59425İstismar yok | vLLM vulnerable to timing attack at bearer authvllm · vllm · CWE-385 | Yüksek7,5 | — | %0,6 | 7 Eki 2025 |
29İzleyin | CVE-2023-46809İstismar yok | Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched arenodejs · node · CWE-385 | Yüksek7,4 | — | %1,3 | 7 Eyl 2024 |
29İzleyin | CVE-2025-0306İstismar yok | Ruby: openssl: ruby marvin attackred hat · red hat enterprise linux 10 · CWE-385 | Yüksek7,4 | — | %0,6 | 9 Oca 2025 |
28İzleyin | CVE-2017-2624İstismar yok | It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.x.org · x server · CWE-385 | Yüksek7,0 | — | %0,7 | 27 Tem 2018 |
27İzleyin | CVE-2025-9231İstismar yok | Timing side-channel in SM2 algorithm on 64 bit ARMopenssl · openssl · CWE-385 | Orta6,5 | — | %2,2 | 30 Eyl 2025 |
26İzleyin | CVE-2026-6478İstismar yok | PostgreSQL discloses MD5-hashed passwords via covert timing channelpostgresql · postgresql · CWE-385 | Orta6,5 | — | %0,6 | 14 May 2026 |
24İzleyin | CVE-2018-10844İstismar yok | It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Orta5,9 | — | %3,6 | 22 Ağu 2018 |
24İzleyin | CVE-2018-10845İstismar yok | It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.gnu · gnutls · CWE-385 | Orta5,9 | — | %3,6 | 22 Ağu 2018 |
24İzleyin | CVE-2020-25659İstismar yok | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Orta5,9 | — | %2,4 | 11 Oca 2021 |
24İzleyin | CVE-2020-25657İstismar yok | A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API m2crypto project · m2crypto · CWE-385 | Orta5,9 | — | %1,7 | 12 Oca 2021 |
23İzleyin | CVE-2020-25658İstismar yok | It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.python-rsa project · python-rsa · CWE-385 | Orta5,9 | — | %1,7 | 12 Kas 2020 |
23İzleyin | CVE-2024-2236İstismar yok | Libgcrypt: vulnerable to marvin attackred hat · red hat enterprise linux 9 · CWE-385 | Orta5,9 | — | %1,1 | 6 Mar 2024 |
23İzleyin | CVE-2024-26306İstismar yok | iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption es · iperf3 · CWE-385 | Orta5,9 | — | %1,1 | 14 May 2024 |
23İzleyin | CVE-2023-49092İstismar yok | RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannelsrustcrypto · rsa · CWE-385 | Orta5,9 | — | %0,6 | 28 Kas 2023 |
22İzleyin | CVE-2016-7056İstismar yok | A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 privaopenssl · openssl · CWE-385 | Orta5,5 | — | %0,6 | 10 Eyl 2018 |
22İzleyin | CVE-2018-10846İstismar yok | A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.gnu · gnutls · CWE-385 | Orta5,6 | — | %0,4 | 22 Ağu 2018 |
- CVE-2020-2950639İzleyin
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable T
KritikCVSS 9,8İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition11 Tem 2022
- CVE-2020-3516639İzleyin
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
KritikCVSS 9,8İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition11 Tem 2022
- CVE-2026-559835İzleyin
Non-constant time comparisons risk private key leakage in FrodoKEM.
YüksekCVSS 8,9İstismar yokEPSS %1legion of the bouncy castle inc. · bc-java15 Nis 2026
- CVE-2020-3516432İzleyin
Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Tim
YüksekCVSS 8,1İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition11 Tem 2022
- GHSA-hvh4-5qr6-3v7r32İzleyin
Observable Timing Discrepancy in pypqc
YüksekCVSS 8,2İstismar yokPyPI · pypqc5 Haz 2024
- CVE-2023-364031İzleyin
Kernel: x86/mm: a per-cpu entry area leak was identified through the init_cea_offsets function when prefetchnta and prefetcht2 instructions being used for the p
YüksekCVSS 7,8Kavram kanıtıEPSS %1linux · linux kernel24 Tem 2023
- CVE-2019-373230İzleyin
RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite
YüksekCVSS 7,5İstismar yokEPSS %1dell · bsafe crypto-c-micro-edition30 Eyl 2019
- CVE-2022-2440930İzleyin
Dell BSAFE SSL-J contains remediation for a covert timing channel vulnerability that may be exploited by malicious users to compromise the a
YüksekCVSS 7,5İstismar yokEPSS %1dell · bsafe ssl-j23 Şub 2022
- CVE-2024-2596430İzleyin
Dell PowerScale OneFS 9.5.0.x through 9.7.0.x contain a covert timing channel vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %1dell · powerscale onefs25 Mar 2024
- CVE-2025-5942530İzleyin
vLLM vulnerable to timing attack at bearer auth
YüksekCVSS 7,5İstismar yokEPSS %1vllm · vllm7 Eki 2025
- CVE-2023-4680929İzleyin
Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are
YüksekCVSS 7,4İstismar yokEPSS %1nodejs · node7 Eyl 2024
- CVE-2025-030629İzleyin
Ruby: openssl: ruby marvin attack
YüksekCVSS 7,4İstismar yokEPSS %1red hat · red hat enterprise linux 109 Oca 2025
- CVE-2017-262428İzleyin
It was found that xorg-x11-server before 1.19.0 including uses memcmp() to check the received MIT cookie against a series of valid cookies.
YüksekCVSS 7,0İstismar yokEPSS %1x.org · x server27 Tem 2018
- CVE-2025-923127İzleyin
Timing side-channel in SM2 algorithm on 64 bit ARM
OrtaCVSS 6,5İstismar yokEPSS %2openssl · openssl30 Eyl 2025
- CVE-2026-647826İzleyin
PostgreSQL discloses MD5-hashed passwords via covert timing channel
OrtaCVSS 6,5İstismar yokEPSS %1postgresql · postgresql14 May 2026
- CVE-2018-1084424İzleyin
It was found that the GnuTLS implementation of HMAC-SHA-256 was vulnerable to a Lucky thirteen style attack.
OrtaCVSS 5,9İstismar yokEPSS %4gnu · gnutls22 Ağu 2018
- CVE-2018-1084524İzleyin
It was found that the GnuTLS implementation of HMAC-SHA-384 was vulnerable to a Lucky thirteen style attack.
OrtaCVSS 5,9İstismar yokEPSS %4gnu · gnutls22 Ağu 2018
- CVE-2020-2565924İzleyin
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
OrtaCVSS 5,9İstismar yokEPSS %2cryptography.io · cryptography11 Oca 2021
- CVE-2020-2565724İzleyin
A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API
OrtaCVSS 5,9İstismar yokEPSS %2m2crypto project · m2crypto12 Oca 2021
- CVE-2020-2565823İzleyin
It was found that python-rsa is vulnerable to Bleichenbacher timing attacks.
OrtaCVSS 5,9İstismar yokEPSS %2python-rsa project · python-rsa12 Kas 2020
- CVE-2024-223623İzleyin
Libgcrypt: vulnerable to marvin attack
OrtaCVSS 5,9İstismar yokEPSS %1red hat · red hat enterprise linux 96 Mar 2024
- CVE-2024-2630623İzleyin
iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption
OrtaCVSS 5,9İstismar yokEPSS %1es · iperf314 May 2024
- CVE-2023-4909223İzleyin
RustCrypto/RSA vulnerable to a Marvin Attack via key recovery through timing sidechannels
OrtaCVSS 5,9İstismar yokEPSS %1rustcrypto · rsa28 Kas 2023
- CVE-2016-705622İzleyin
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 priva
OrtaCVSS 5,5İstismar yokEPSS %1openssl · openssl10 Eyl 2018
- CVE-2018-1084622İzleyin
A cache-based side channel in GnuTLS implementation that leads to plain text recovery in cross-VM attack setting was found.
OrtaCVSS 5,6İstismar yokEPSS %0gnu · gnutls22 Ağu 2018