cryptopp kayıtları
cryptopp üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-203 Observable Discrepancy2
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-327 Use of a Broken or Risky Cryptographic Algorithm1
- CWE-399 Resource Management Errors1
- CWE-417 Communication Channel Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-28285İstismar yok | A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reCWE-209 | Kritik9,8 | — | %0,5 | 14 May 2024 |
31İzleyin | CVE-2016-9939İstismar yok | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.cryptopp · crypto\+\+ · CWE-20 | Yüksek7,5 | — | %4,2 | 30 Oca 2017 |
31İzleyin | CVE-2016-7544İstismar yok | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.microsoft · windows · CWE-399 | Yüksek7,5 | — | %2,7 | 30 Oca 2017 |
31İzleyin | CVE-2016-3995İstismar yok | The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.cryptopp · crypto\+\+ · CWE-200 | Yüksek7,5 | — | %1,9 | 13 Şub 2017 |
30İzleyin | CVE-2022-48570İstismar yok | Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-787 | Yüksek7,5 | — | %1,0 | 22 Ağu 2023 |
30İzleyin | CVE-2023-50980İstismar yok | gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data cryptopp · crypto\+\+ | Yüksek7,5 | — | %0,8 | 18 Ara 2023 |
30İzleyin | CVE-2023-50981İstismar yok | ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pubcryptopp · crypto\+\+ · CWE-835 | Yüksek7,5 | — | %0,8 | 18 Ara 2023 |
24İzleyin | CVE-2019-14318İstismar yok | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.cryptopp · crypto\+\+ · CWE-417 | Orta5,9 | — | %2,7 | 30 Tem 2019 |
24İzleyin | CVE-2016-7420İstismar yok | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert callscryptopp · crypto\+\+ · CWE-200 | Orta5,9 | — | %2,0 | 16 Eyl 2016 |
23İzleyin | CVE-2021-40530İstismar yok | The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic librariescryptopp · crypto\+\+ · CWE-327 | Orta5,9 | — | %1,2 | 6 Eyl 2021 |
23İzleyin | CVE-2023-50979İstismar yok | Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.cryptopp · crypto\+\+ · CWE-203 | Orta5,9 | — | %0,6 | 18 Ara 2023 |
22İzleyin | CVE-2021-43398İstismar yok | Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().cryptopp · crypto\+\+ · CWE-203 | Orta5,3 | — | %2,0 | 4 Kas 2021 |
21İzleyin | CVE-2015-2141İstismar yok | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabcryptopp · crypto\+\+ library · CWE-200 | Orta5,0 | — | %2,9 | 1 Tem 2015 |
21İzleyin | CVE-2017-9434İstismar yok | Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.cryptopp · crypto\+\+ · CWE-125 | Orta5,3 | — | %1,4 | 5 Haz 2017 |
- CVE-2024-2828539İzleyin
A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-re
KritikCVSS 9,8İstismar yokEPSS %114 May 2024
- CVE-2016-993931İzleyin
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine.
YüksekCVSS 7,5İstismar yokEPSS %4cryptopp · crypto\+\+30 Oca 2017
- CVE-2016-754431İzleyin
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions.
YüksekCVSS 7,5İstismar yokEPSS %3microsoft · windows30 Oca 2017
- CVE-2016-399531İzleyin
The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.
YüksekCVSS 7,5İstismar yokEPSS %2cryptopp · crypto\+\+13 Şub 2017
- CVE-2022-4857030İzleyin
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation.
YüksekCVSS 7,5İstismar yokEPSS %1cryptopp · crypto\+\+22 Ağu 2023
- CVE-2023-5098030İzleyin
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data
YüksekCVSS 7,5İstismar yokEPSS %1cryptopp · crypto\+\+18 Ara 2023
- CVE-2023-5098130İzleyin
ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER pub
YüksekCVSS 7,5İstismar yokEPSS %1cryptopp · crypto\+\+18 Ara 2023
- CVE-2019-1431824İzleyin
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation.
OrtaCVSS 5,9İstismar yokEPSS %3cryptopp · crypto\+\+30 Tem 2019
- CVE-2016-742024İzleyin
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls
OrtaCVSS 5,9İstismar yokEPSS %2cryptopp · crypto\+\+16 Eyl 2016
- CVE-2021-4053023İzleyin
The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries
OrtaCVSS 5,9İstismar yokEPSS %1cryptopp · crypto\+\+6 Eyl 2021
- CVE-2023-5097923İzleyin
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.
OrtaCVSS 5,9İstismar yokEPSS %1cryptopp · crypto\+\+18 Ara 2023
- CVE-2021-4339822İzleyin
Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey().
OrtaCVSS 5,3İstismar yokEPSS %2cryptopp · crypto\+\+4 Kas 2021
- CVE-2015-214121İzleyin
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rab
OrtaCVSS 5,0İstismar yokEPSS %3cryptopp · crypto\+\+ library1 Tem 2015
- CVE-2017-943421İzleyin
Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.
OrtaCVSS 5,3İstismar yokEPSS %1cryptopp · crypto\+\+5 Haz 2017