Skip to main content

Vendor archive

bouncycastle CVEs

Beta · best-effort

25 CVEs tagged to vendor bouncycastle2 Critical, 10 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2023-33201

Published Jul 5, 2023

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to val…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-45146

Published Nov 21, 2022

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1000352

Published Jun 4, 2018

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been remove…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000344

Published Jun 4, 2018

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been remove…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000340

Published Jun 4, 2018

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13098

Published Dec 13, 2017

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any T…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-2427

Published Apr 18, 2016

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7940

Published Nov 9, 2015

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obtain private keys via a series…

CVSS 5.0 · Medium
Showing 1-25 of 25 CVEsPage 1 of 1