cryptography.io kayıtları
cryptography.io üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference2
- CWE-295 Improper Certificate Validation2
- CWE-203 Observable Discrepancy1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-385 Covert Timing Channel1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2020-36242İstismar yok | In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could resultcryptography.io · cryptography · CWE-190 | Kritik9,1 | — | %6,7 | 7 Şub 2021 |
32İzleyin | CVE-2026-26007İstismar yok | cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curvescryptography.io · cryptography · CWE-345 | Yüksek8,2 | — | %0,3 | 10 Şub 2026 |
31İzleyin | CVE-2016-9243İstismar yok | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.cryptography.io · cryptography | Yüksek7,5 | — | %3,5 | 27 Mar 2017 |
30İzleyin | CVE-2023-50782İstismar yok | Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659redhat · ansible automation platform · CWE-203 | Yüksek7,5 | — | %1,1 | 5 Şub 2024 |
30İzleyin | CVE-2023-49083İstismar yok | cryptography vulnerable to NULL-dereference when loading PKCS7 certificatescryptography.io · cryptography · CWE-476 | Yüksek7,5 | — | %1,0 | 29 Kas 2023 |
30İzleyin | CVE-2024-26130İstismar yok | cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash overcryptography.io · cryptography · CWE-476 | Yüksek7,5 | — | %0,8 | 21 Şub 2024 |
30İzleyin | CVE-2023-38325İstismar yok | The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.cryptography.io · cryptography · CWE-295 | Yüksek7,5 | — | %0,7 | 14 Tem 2023 |
27İzleyin | CVE-2026-39892İstismar yok | cryptography has a buffer overflow if non-contiguous buffers were passed to APIscryptography.io · cryptography · CWE-119 | Orta6,9 | — | %0,8 | 8 Nis 2026 |
26İzleyin | CVE-2023-23931İstismar yok | Cipher.update_into can corrupt memory in pyca cryptographycryptography.io · cryptography · CWE-754 | Orta6,5 | — | %1,3 | 7 Şub 2023 |
24İzleyin | CVE-2020-25659İstismar yok | python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5 cryptography.io · cryptography · CWE-385 | Orta5,9 | — | %2,4 | 11 Oca 2021 |
6İzleyin | CVE-2026-34073İstismar yok | cryptography has incomplete DNS name constraint enforcement on peer namescryptography.io · cryptography · CWE-295 | Düşük1,7 | — | %0,2 | 30 Mar 2026 |
- CVE-2020-3624238İzleyin
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result
KritikCVSS 9,1İstismar yokEPSS %7cryptography.io · cryptography7 Şub 2021
- CVE-2026-2600732İzleyin
cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves
YüksekCVSS 8,2İstismar yokEPSS %0cryptography.io · cryptography10 Şub 2026
- CVE-2016-924331İzleyin
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
YüksekCVSS 7,5İstismar yokEPSS %3cryptography.io · cryptography27 Mar 2017
- CVE-2023-5078230İzleyin
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
YüksekCVSS 7,5İstismar yokEPSS %1redhat · ansible automation platform5 Şub 2024
- CVE-2023-4908330İzleyin
cryptography vulnerable to NULL-dereference when loading PKCS7 certificates
YüksekCVSS 7,5İstismar yokEPSS %1cryptography.io · cryptography29 Kas 2023
- CVE-2024-2613030İzleyin
cryptography NULL pointer deference with pkcs12.serialize_key_and_certificates when called with a non-matching certificate and private key and an hmac_hash over
YüksekCVSS 7,5İstismar yokEPSS %1cryptography.io · cryptography21 Şub 2024
- CVE-2023-3832530İzleyin
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
YüksekCVSS 7,5İstismar yokEPSS %1cryptography.io · cryptography14 Tem 2023
- CVE-2026-3989227İzleyin
cryptography has a buffer overflow if non-contiguous buffers were passed to APIs
OrtaCVSS 6,9İstismar yokEPSS %1cryptography.io · cryptography8 Nis 2026
- CVE-2023-2393126İzleyin
Cipher.update_into can corrupt memory in pyca cryptography
OrtaCVSS 6,5İstismar yokEPSS %1cryptography.io · cryptography7 Şub 2023
- CVE-2020-2565924İzleyin
python-cryptography 3.2 is vulnerable to Bleichenbacher timing attacks in the RSA decryption API, via timed processing of valid PKCS#1 v1.5
OrtaCVSS 5,9İstismar yokEPSS %2cryptography.io · cryptography11 Oca 2021
- CVE-2026-340736İzleyin
cryptography has incomplete DNS name constraint enforcement on peer names
DüşükCVSS 1,7İstismar yokEPSS %0cryptography.io · cryptography30 Mar 2026