Nettle Project
Nettle Project Nettle: vulnerabilidades y CVE
Nettle Project Nettle tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-36660 | Crítica (9.8) | 1.0% | — | 25 jun 2023 | The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. |
| CVE-2021-3580 | Alta (7.5) | 2.7% | — | 5 ago 2021 | A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. |
| CVE-2021-20305 | Alta (8.1) | 1.7% | — | 5 abr 2021 | A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called… |
| CVE-2018-16869 | Media (5.7) | 1.5% | — | 3 dic 2018 | A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core… |
| CVE-2016-6489 | Alta (7.5) | 5.0% | — | 14 abr 2017 | The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. |
| CVE-2015-8805 | Crítica (9.8) | 2.8% | — | 23 feb 2016 | The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have… |
| CVE-2015-8804 | Crítica (9.8) | 3.9% | — | 23 feb 2016 | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified… |
| CVE-2015-8803 | Crítica (9.8) | 4.2% | — | 23 feb 2016 | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have… |