Vulnerability index

Browse CVEs

26 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-44378 Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in t… Botan 3.12.0+ Fix from $1,9502026-05-27 CRITICAL 9.1 CVE-2026-34582 Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the… Botan after 3.11.0 Fix from $2,3002026-04-07 HIGH 7.5 CVE-2026-34580 Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any … Botan Mitigation only Fix from $1,9502026-04-07 MEDIUM 5.9 CVE-2026-32884 Botan is a C++ cryptography library. Prior to version 3.11.0, during processing of an X.509 certificate path using name constraints which restrict th… Botan 3.11.0+ Fix from $1,6002026-03-30 HIGH 8.2 CVE-2026-32877 Botan is a C++ cryptography library. From version 2.3.0 to before version 3.11.0, during SM2 decryption, the code that checked the authentication cod… Botan 3.11.0+ Fix from $1,9502026-03-30 MEDIUM 5.9 CVE-2026-32883 Botan is a C++ cryptography library. From version 3.0.0 to before version 3.11.0, during X509 path validation, OCSP responses were checked for an app… Botan 3.11.0+ Fix from $1,6002026-03-30 MEDIUM 5.9 CVE-2024-50382 Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent control flow in lib/utils/ghash/ghash.cpp in GHASH in … Botan 3.6.0+ Fix from $1,6002024-10-23 MEDIUM 5.9 CVE-2024-50383 Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used i… Botan 3.6.0+ Fix from $1,6002024-10-23 MEDIUM 5.3 CVE-2024-39312 Botan is a C++ cryptography library. X.509 certificates can identify elliptic curves using either an object identifier or using explicit encoding of … Botan 2.19.5 / 3.5.0+ Fix from $1,6002024-07-08 HIGH 7.5 CVE-2017-7252 bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier f… Botan 2.1.0+ Fix from $1,9502023-11-03 CRITICAL 9.1 CVE-2022-43705 In Botan before 2.19.3, it is possible to forge OCSP responses due to a certificate verification error. This issue was introduced in Botan 1.11.34 (N… Botan 2.19.3+ Fix from $2,3002022-11-27 CRITICAL 9.8 CVE-2021-24115 In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex). Botan 2.17.3+ Fix from $2,3002021-02-22 MEDIUM 5.9 CVE-2018-20187 A side-channel issue was discovered in Botan before 2.9.0. An attacker capable of precisely measuring the time taken for ECC key generation may be ab… Botan 2.9.0+ Fix from $1,6002019-03-08 MEDIUM 5.9 CVE-2018-12435 Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or … Botan after 2.7.0 Fix from $1,6002018-06-15 HIGH 7.5 CVE-2018-9860 An issue was discovered in Botan 1.11.32 through 2.x before 2.6.0. An off-by-one error when processing malformed TLS-CBC ciphertext could cause the r… Botan 2.6.0+ Fix from $1,9502018-04-12 CRITICAL 9.8 CVE-2018-9127 Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, unde… Botan after 2.4.0 Fix from $2,3002018-04-02 CRITICAL 9.8 CVE-2017-2801 A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certif… Botan No fix yet Fix from $2,3002017-05-24 CRITICAL 9.8 CVE-2015-7826 botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via… Botan after 1.11.21 Fix from $2,3002017-04-10 CRITICAL 9.8 CVE-2016-6878 The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via v… Botan after 1.11.30 Fix from $2,3002017-04-10 HIGH 7.5 CVE-2015-7824 botan 1.11.x before 1.11.22 makes it easier for remote attackers to decrypt TLS ciphertext data via a padding-oracle attack against TLS CBC ciphersui… Botan after 1.11.21 Fix from $1,9502017-04-10 HIGH 7.5 CVE-2015-7825 botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory con… Botan after 1.11.21 Fix from $1,9502017-04-10 HIGH 7.5 CVE-2016-6879 The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call wit… Botan Mitigation only Fix from $1,9502017-04-10 CRITICAL 9.8 CVE-2016-9132 In Botan 1.8.0 through 1.11.33, when decoding BER data an integer overflow could occur, which would cause an incorrect length field to be computed. S… Botan Patch available Fix from $2,3002017-01-30 MEDIUM 6.2 CVE-2016-8871 In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be… Botan Mitigation only Fix from $1,6002016-10-28 CRITICAL 9.8 CVE-2016-2196EPSS 5% Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memor… Botan Mitigation only Fix from $2,3002016-05-13 HIGH 7.5 CVE-2014-9742 The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remo… Botan after 1.10.7 Fix from $1,9502016-05-13