Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-50980 gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(… Crypto\+\+ after 8.9.0 Fix from $1,9502023-12-18 HIGH 7.5 CVE-2023-50981 ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key d… Crypto\+\+ after 8.9.0 Fix from $1,9502023-12-18 MEDIUM 5.9 CVE-2023-50979 Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding. Crypto\+\+ after 8.9.0 Fix from $1,6002023-12-18 HIGH 7.5 CVE-2022-48570 Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outsi… Crypto\+\+ after 8.4.0 Fix from $1,9502023-08-22 MEDIUM 5.3 CVE-2021-43398 Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and priva… Crypto\+\+ after 8.6.0 Fix from $1,6002021-11-04 MEDIUM 5.9 CVE-2019-14318 Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the … Crypto\+\+ after 8.3.0 Fix from $1,6002019-07-30 MEDIUM 5.3 CVE-2017-9434 Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter. Crypto\+\+ after 5.6.4 Fix from $1,6002017-06-05 HIGH 7.5 CVE-2016-3995 The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may b… Crypto\+\+ after 5.6.3 Fix from $1,9502017-02-13 HIGH 7.5 CVE-2016-7544 Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in… Crypto\+\+ Patch available Fix from $1,9502017-01-30 MEDIUM 5.9 CVE-2016-7420 Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are… Crypto\+\+ after 5.6.4 Fix from $1,6002016-09-16 MEDIUM 5.0 CVE-2015-2141 The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Willia… Crypto\+\+ Library Patch available Fix from $1,6002015-07-01