Skip to main content

CWE archive

CWE-361 CVEs

Programmatic archive

7 CVEs tagged with CWE-3612 Critical, 3 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2016-7037

Published Jan 23, 2017

The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signature…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7036

Published Jan 23, 2017

python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1643

Published Mar 13, 2016

The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly mai…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1