İçeriğe atla
Noroxi

cryptography.io kayıtları

cryptography.io üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%100
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2020-36242
    38İzleyin

    In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result

    KritikCVSS 9,1İstismar yokEPSS %7

    cryptography.io · cryptography7 Şub 2021

  • CVE-2026-26007
    32İzleyin

    cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves

    YüksekCVSS 8,2İstismar yokEPSS %0

    cryptography.io · cryptography10 Şub 2026

  • CVE-2016-9243
    31İzleyin

    HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

    YüksekCVSS 7,5İstismar yokEPSS %3

    cryptography.io · cryptography27 Mar 2017

  • CVE-2023-50782
    30İzleyin

    Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659

    YüksekCVSS 7,5İstismar yokEPSS %1

    redhat · ansible automation platform5 Şub 2024

  • CVE-2023-49083
    30İzleyin

    cryptography vulnerable to NULL-dereference when loading PKCS7 certificates

    YüksekCVSS 7,5İstismar yokEPSS %1

    cryptography.io · cryptography29 Kas 2023

  • CVE-2024-26130
    30İzleyin

    cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash over

    YüksekCVSS 7,5İstismar yokEPSS %1

    cryptography.io · cryptography21 Şub 2024

  • CVE-2023-38325
    30İzleyin

    The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.

    YüksekCVSS 7,5İstismar yokEPSS %1

    cryptography.io · cryptography14 Tem 2023

  • CVE-2026-39892
    27İzleyin

    cryptography has a buffer overflow if non-contiguous buffers were passed to APIs

    OrtaCVSS 6,9İstismar yokEPSS %1

    cryptography.io · cryptography8 Nis 2026

  • CVE-2023-23931
    26İzleyin

    Cipher.update_into can corrupt memory in pyca cryptography

    OrtaCVSS 6,5İstismar yokEPSS %1

    cryptography.io · cryptography7 Şub 2023

  • CVE-2020-25659
    24İzleyin

    python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5

    OrtaCVSS 5,9İstismar yokEPSS %2

    cryptography.io · cryptography11 Oca 2021

  • cryptography has incomplete DNS name constraint enforcement on peer names

    DüşükCVSS 1,7İstismar yokEPSS %0

    cryptography.io · cryptography30 Mar 2026