Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Libgcrypt MEDIUM 6.7
CVE-2026-41989

Libgcrypt before 1.12.2 sometimes allows a heap-based buffer overflow and denial of service via crafted ECDH ciphertext to gcry_pk_decrypt.

Fix: 1.10.4 / 1.11.3+
Fix from $1,600 2026-04-23
Gnupg CRITICAL 9.8
CVE-2026-24881

In GnuPG before 2.5.17, a crafted CMS (S/MIME) EnvelopedData message carrying an oversized wrapped session key can cause a stack-based buffer overflo…

Fix: 2.5.17 / 5.0.1+
Fix from $2,300 2026-01-27
Gnupg HIGH 7.8
CVE-2026-24882

In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.

Fix: 2.5.17 / 5.0.1+
Fix from $1,950 2026-01-27
Gnupg MEDIUM 5.5
CVE-2026-24883

In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a de…

Fix: 2.5.17 / 5.0.1+
Fix from $1,600 2026-01-27
Gnupg HIGH 7.0
CVE-2025-68973

In GnuPG before 2.4.9, armor_filter in g10/armor.c has two increments of an index variable where one is intended, leading to an out-of-bounds write f…

Fix: after 2.4.8
Fix from $1,950 2025-12-28
Libksba CRITICAL 9.8
CVE-2022-3515

A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for co…

Fix: 1.6.3 / 2.2.41+
Fix from $2,300 2023-01-12
Libgcrypt MEDIUM 5.9
CVE-2021-40528

The ElGamal implementation in Libgcrypt before 1.9.4 allows plaintext recovery because, during interaction between two cryptographic libraries, a cer…

Fix: 1.9.4+
Fix from $1,600 2021-09-06
Libgcrypt HIGH 7.8
CVE-2021-3345

_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large …

Patch available
Fix from $1,950 2021-01-29
Gnupg HIGH 7.8
CVE-2020-25125

GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an…

Patch available
Fix from $1,950 2020-09-03
Libgcrypt MEDIUM 5.9
CVE-2019-12904

In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to o…

Patch available
Fix from $1,600 2019-06-20
Libgcrypt HIGH 7.5
CVE-2018-6829

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain …

Fix: after 1.8.2
Fix from $1,950 2018-02-07
Libgcrypt MEDIUM 5.9
CVE-2017-9526

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover…

Fix: after 1.7.6
Fix from $1,600 2017-06-11
Gnupg MEDIUM 5.8
CVE-2013-4351

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted)…

Mitigation only
Fix from $1,600 2013-10-10
Gnupg MEDIUM 5.8
CVE-2012-6085

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corru…

No fix yet
Fix from $1,600 2013-01-24
Gnupg HIGH 9.3
CVE-2008-1530

GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate ke…

Mitigation only
Fix from $1,950 2008-03-27
Gnupg MEDIUM 6.8
CVE-2006-6169

Heap-based buffer overflow in the ask_outfile_name function in openfile.c for GnuPG (gpg) 1.4 and 2.0, when running interactively, might allow attack…

Patch available
Fix from $1,600 2006-11-29
Gnupg MEDIUM 5.0
CVE-2006-3746EPSS 7%

Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted messag…

No fix yet
Fix from $1,600 2006-07-28
Gnupg MEDIUM 5.0
CVE-2006-3082EPSS 7%

parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly o…

Fix: after 1.9.20
Fix from $1,600 2006-06-19
Gnupg MEDIUM 5.0
CVE-2005-0366

The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recov…

Fix: 1.4.1+
Fix from $1,600 2005-05-02