Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
Nimbus Jose\+jwt
HIGH 7.5
CVE-2023-52428
In Connect2id Nimbus JOSE+JWT before 9.37.2, an attacker can cause a denial of service (resource consumption) via a large JWE p2c header value (aka i…
Fix: 9.37.2+
Fix from $1,950
2024-02-11
Nimbus Jose\+jwt
HIGH 7.5
CVE-2017-12972
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduc…
Patch available
Fix from $1,950
2017-08-20
Nimbus Jose\+jwt
HIGH 7.5
CVE-2017-12974
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which a…
Patch available
Fix from $1,950
2017-08-20