Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bouncy Castle For Java MEDIUM 5.5
CVE-2023-33202

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser cla…

Fix: 1.0.2.4 / 1.73+
Fix from $1,600 2023-11-23
Bc Java MEDIUM 5.3
CVE-2023-33201

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertS…

Fix: 1.74+
Fix from $1,600 2023-07-05
Fips Java Api MEDIUM 5.5
CVE-2022-45146

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigge…

Fix: 1.0.2.4+
Fix from $1,600 2022-11-21
Bc Csharp MEDIUM 5.9
CVE-2020-15522

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the …

Fix: 1.0.1.1 / 1.0.1.2+
Fix from $1,600 2021-05-20
Fips Java Api MEDIUM 5.3
CVE-2020-26939

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because …

Fix: 1.0.1.2 / 1.61+
Fix from $1,600 2020-11-02
Bc Java CRITICAL 9.8
CVE-2018-1000613

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externall…

Fix: 1.60+
Fix from $2,300 2018-07-09
Bc Java HIGH 7.4
CVE-2016-1000344

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and …

Fix: after 1.55
Fix from $1,950 2018-06-04
Bc Java HIGH 7.4
CVE-2016-1000352

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and …

Fix: after 1.55
Fix from $1,950 2018-06-04
Bc Java HIGH 7.5
CVE-2016-1000340

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw mat…

Fix: after 1.55
Fix from $1,950 2018-06-04
Bc Java MEDIUM 5.9
CVE-2017-13098EPSS 24%

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bl…

Fix: 1.59+
Fix from $1,600 2017-12-13
Bc Java MEDIUM 5.5
CVE-2016-2427

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it e…

Mitigation only
Fix from $1,600 2016-04-18
Bc Java HIGH 10.0
CVE-2007-6721

The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and rem…

Fix: after 1.37
Fix from $1,950 2009-03-30