Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 2.0% | — | Golang CryptoDebian Linux | 22/5/2019 | 17/6/2026 | A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain one or more optional "Hash" Armor Headers. The "Hash" Armor Header… | |
| Analizada | Media (5.9) | 3.5% | — | Golang CryptoDebian Linux | 9/5/2019 | 17/6/2026 | An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/salsa packages. If more than 256 GiB of keystream is generated, or if the… | |
| Modificada | Alta (7.5) | 1.3% | — | Cryptobots Battletoken | 15/3/2019 | 17/6/2026 | An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user. | |
| Modificada | Crítica (9.8) | 2.3% | — | Irisnet-crypto | 25/2/2019 | 17/6/2026 | In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage. | |
| Modificada | Alta (7.5) | 1.3% | — | Cryptosaga | 24/9/2018 | 17/6/2026 | The random() function of the smart contract implementation for CryptoSaga, an Ethereum game, generates a random value with publicly readable variables such as timestamp, the current block's blockhash, and a private variable (which can be read with a getStorageAt call). Therefore, attackers can precompute the random… | |
| Modificada | Crítica (9.8) | 4.0% | — | Dell BsafeDell Bsafe Crypto-cOracle Application Testing SuiteOracle Communications Analytics+9 | 14/9/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result… | |
| Modificada | Media (5.9) | 1.7% | — | Dell Bsafe Crypto-jDell RSA Bsafe Ssl-j | 11/9/2018 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.4 and RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during PKCS #1 unpadding operations, also known as a Bleichenbacher attack. A remote attacker may be able to recover a RSA key. | |
| Modificada | Media (6.5) | 1.9% | — | Dell BsafeDell Bsafe Crypto-cOracle Application Testing SuiteOracle Communications Analytics+9 | 31/8/2018 | 17/6/2026 | RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would… | |
| Modificada | Alta (7.5) | 1.8% | — | Pycryptodome | 20/8/2018 | 17/6/2026 | PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16 bytes. | |
| Modificada | Media (5.9) | 1.4% | — | Mycryptochamp | 7/8/2018 | 17/6/2026 | The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random value with publicly readable variables such as the current block information and a private variable, (which can be read with a getStorageAt call). Therefore, attackers can get powerful champs/items and… | |
| Modificada | Alta (7.5) | 1.1% | — | Megacryptopolis | 6/8/2018 | 17/6/2026 | The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not… | |
| Modificada | Alta (7.5) | 1.3% | — | Cryptogs | 3/8/2018 | 17/6/2026 | The endCoinFlip function and throwSlammer function of the smart contract implementations for Cryptogs, an Ethereum game, generate random numbers with an old block's hash. Therefore, attackers can predict the random number and always win the game. | |
| Modificada | Alta (7.5) | 3.2% | — | Python-cryptographyRedhat OpenstackCanonical Ubuntu Linux | 30/7/2018 | 17/6/2026 | A flaw was found in python-cryptography versions between >=1.9.0 and <2.3. The finalize_with_tag API did not enforce a minimum tag length. If a user did not validate the input length prior to passing it to finalize_with_tag an attacker could craft an invalid payload with a shortened tag (e.g. 1 byte) such that they… | |
| Modificada | Crítica (9.8) | 7.5% | — | Microsoft Research Javascript Cryptography Library | 11/7/2018 | 17/6/2026 | A Security Feature Bypass vulnerability exists in MSR JavaScript Cryptography Library that is caused by incorrect arithmetic computations, aka "MSR JavaScript Cryptography Library Security Feature Bypass Vulnerability." This affects Microsoft Research JavaScript Cryptography Library. | |
| Modificada | Alta (7.5) | 1.1% | — | Cryptosistoken Project Cryptosistoken | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CryptosisToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Cryptoleu Project Cryptoleu | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CryptoLeu, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Crypto Alley Shares Project Crypto Alley Shares | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Crypto Alley Shares (CAST), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Providence Crypto Casino | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for Providence Crypto Casino (PVE) (Contract Name: ProvidenceCasinoToken), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. | |
| Modificada | Alta (7.5) | 1.1% | — | Cryptoabs Project Cryptoabs | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CryptoABS (ABS), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Cryptonitexcoin Project Cryptonitexcoin | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for CryptonitexCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (4.7) | 0.29% | — | Intel Integrated Performance Primitives Cryptography | 5/6/2018 | 17/6/2026 | Some implementations in Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1 do not properly ensure constant execution time. | |
| Modificada | Alta (8.8) | 1.7% | — | Cryptonote | 13/3/2018 | 17/6/2026 | CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution and a takeover of the cryptocurrency wallet if an attacker can… | |
| Modificada | Alta (7.5) | 2.0% | — | Dlitz PycryptoDebian LinuxCanonical Ubuntu Linux | 3/2/2018 | 17/6/2026 | lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold… | |
| Modificada | Media (5.3) | 1.4% | — | Cryptopp Crypto++ | 5/6/2017 | 17/6/2026 | Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter. | |
| Modificada | Alta (8.1) | 3.2% | — | Golang Crypto | 4/4/2017 | 17/6/2026 | The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism. |