Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.5% | — | Cryptography.io CryptographyFedoraproject FedoraCanonical Ubuntu Linux | 27/3/2017 | 17/6/2026 | HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size. | |
| Modificada | Alta (7.3) | 0.97% | — | Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+8 | 28/2/2017 | 17/6/2026 | Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel… | |
| Modificada | Crítica (9.8) | 9.6% | — | Dlitz PycryptoFedoraproject Fedora | 15/2/2017 | 17/6/2026 | Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py. | |
| Modificada | Alta (7.5) | 1.9% | — | Cryptopp Crypto++ | 13/2/2017 | 17/6/2026 | The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compiler, which allows attackers to conduct timing attacks. | |
| Modificada | Baja (3.7) | 1.5% | — | Dell Bsafe Crypto-j | 3/2/2017 | 17/6/2026 | EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed the modified PKCS#12 file to the toolkit and guess the current… | |
| Modificada | Alta (7.5) | 1.9% | — | Dell Bsafe Crypto-j | 3/2/2017 | 17/6/2026 | An issue was discovered in EMC RSA BSAFE Crypto-J versions prior to 6.2.2. There is an Improper OCSP Validation Vulnerability. OCSP responses have two time values: thisUpdate and nextUpdate. These specify a validity period; however, both values are optional. Crypto-J treats the lack of a nextUpdate as indicating that… | |
| Modificada | Alta (7.5) | 4.2% | — | Cryptopp Crypto++Debian Linux | 30/1/2017 | 17/6/2026 | Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 object. If there is not enough content octets in the ASN.1 object, then the function will fail and the memory block will be zeroed even if its… | |
| Modificada | Alta (7.5) | 2.7% | — | Cryptopp Crypto++ | 30/1/2017 | 17/6/2026 | Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed. | |
| Modificada | Media (6.5) | 0.96% | — | Sapcryptolib | 13/10/2016 | 17/6/2026 | The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008. | |
| Modificada | Media (5.9) | 2.0% | — | Cryptopp Crypto++ | 16/9/2016 | 17/6/2026 | Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion… | |
| Modificada | Media (5.3) | 2.2% | — | Latchset Jwcrypto | 1/9/2016 | 17/6/2026 | The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA). | |
| Modificada | Media (5.9) | 3.5% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Crypto-jDell Bsafe Micro-edition-suiteDell Bsafe Ssl-c+1 | 12/4/2016 | 17/6/2026 | EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote attackers to discover a private-key prime by conducting a Lenstra… | |
| Modificada | Media (5) | 4.8% | — | Opensuse LeapOpensuseBouncycastle Bouncy Castle Crypto PackageOracle Application Testing Suite+3 | 9/11/2015 | 17/6/2026 | The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series of crafted elliptic curve Diffie Hellman (ECDH) key exchanges, aka an "invalid curve attack." | |
| Modificada | Crítica (9.8) | 2.6% | — | Dell BsafeDell Bsafe Crypto-cDell Bsafe Ssl-c | 20/8/2015 | 17/6/2026 | Integer underflow in the base64-decoding implementation in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-C Micro Edition (Crypto-C ME) before 4.0.4 and 4.1, and RSA BSAFE SSL-C 2.8.9 and earlier allows remote attackers to cause a denial of service (memory… | |
| Modificada | Media (5) | 2.9% | — | Cryptopp Crypto++ LibraryOpensuse | 1/7/2015 | 17/6/2026 | The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack. | |
| Modificada | Alta (7.5) | 1.3% | — | SAP CommoncryptolibSapcryptolibSapseculibSAP Hana+1 | 4/11/2014 | 17/6/2026 | SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attackers to spoof Digital Signature Algorithm (DSA) signatures via unspecified vectors. | |
| Modificada | Media (4.3) | 1.7% | — | Dlitz Pycrypto | 26/10/2013 | 16/6/2026 | The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is… | |
| Modificada | Media (5.8) | 1.6% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Crypto-j | 11/10/2013 | 16/6/2026 | The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by… | |
| Modificada | Media (4) | 3.0% | — | Bouncycastle Bc-javaBouncycastle Legion-of-the-bouncy-castle-c#-cryptography-api | 8/2/2013 | 16/6/2026 | The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and… | |
| Modificada | Media (6.2) | 0.36% | — | Opencryptoki Project Opencryptoki | 10/10/2012 | 16/6/2026 | openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/. | |
| Modificada | Baja (2.9) | 1.0% | — | Opencryptoki Project Opencryptoki | 10/10/2012 | 16/6/2026 | openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp. | |
| Modificada | Baja (3.6) | 0.46% | — | Fedoraproject Crypto-utils | 10/10/2012 | 16/6/2026 | The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory. | |
| Modificada | Media (6.9) | 0.49% | — | Sophos Free EncryptionSophos Safeguard Privatecrypto | 7/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Sophos Free Encryption 2.40.1.1 and Sophos SafeGuard PrivateCrypto 2.40.1.2 allows local users to gain privileges via a Trojan horse pcrypt0406.dll file in the current working directory, as demonstrated by a directory that contains a .uti file. NOTE: the provenance of this… | |
| Modificada | Media (4.3) | 2.4% | — | Dlitz Pycrypto | 17/6/2012 | 16/6/2026 | PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it easier for attackers to conduct brute force attacks to obtain the private key. | |
| Modificada | Media (5) | 2.0% | — | Captcha Cryptographp | 27/5/2012 | 16/6/2026 | CRLF injection vulnerability in cryptographp.inc.php in Cryptographp allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the cfg parameter. |