Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2565▼ 302 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.52% | — | Tlsfuzzer Ecdsa | 27/3/2026 | 17/6/2026 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Prior to version 0.19.2, an issue in the low-level DER parsing… | |
| Analizada | Alta (7.5) | 1.0% | — | Antonkueltz Fastecdsa | 24/2/2024 | 17/6/2026 | Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary free(), arbitrary realloc(), null… | |
| Analizada | Alta (7.4) | 0.98% | — | Tlsfuzzer Ecdsa | 23/1/2024 | 17/6/2026 | The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (Elliptic Curve Digital Signature Algorithm), EdDSA (Edwards-curve Digital Signature Algorithm) and ECDH (Elliptic Curve Diffie-Hellman). Versions 0.18.0 and prior are vulnerable to the Minerva attack.… | |
| Modificada | Alta (7.5) | 1.0% | — | Ecdsautils Project EcdsautilsFedoraproject FedoraDebian Linux | 6/5/2022 | 17/6/2026 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple… | |
| Modificada | Crítica (9.8) | 1.2% | — | Starkbank Ecdsa-python | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 1.0% | — | Starkbank Ecdsa-node | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 1.0% | — | Starkbank Ecdsa-java | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 1.1% | — | Starkbank Ecdsa-dotnet | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 1.1% | — | Starkbank Elixir Ecdsa | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank Elixir ECDSA library (ecdsa-elixir) 1.0.0 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Alta (7.5) | 1.3% | — | Antonkueltz Fastecdsa | 2/6/2020 | 17/6/2026 | An issue was discovered in fastecdsa before 2.1.2. When using the NIST P-256 curve in the ECDSA implementation, the point at infinity is mishandled. This means that for an extreme value in k and s^-1, the signature verification fails even if the signature is correct. This behavior is not solely a usability problem.… | |
| Modificada | Crítica (9.1) | 1.5% | — | Python-ecdsa Project Python-ecdsaRedhat Ceph StorageRedhat OpenstackRedhat Virtualization | 2/1/2020 | 17/6/2026 | A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper verification, an attacker could use a malleable signature to create… | |
| Modificada | Alta (7.5) | 2.4% | — | Python-ecdsa Project Python-ecdsa | 26/11/2019 | 17/6/2026 | An error-handling flaw was found in python-ecdsa before version 0.13.3. During signature decoding, malformed DER signatures could raise unexpected exceptions (or no exceptions at all), which could lead to a denial of service. |