Skip to main content

Vendor/product archive

bouncycastle / bc-java CVEs

Beta · best-effort

19 CVEs tagged to bouncycastle / bc-java2 Critical, 9 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2023-33201

Published Jul 5, 2023

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to val…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1000352

Published Jun 4, 2018

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been remove…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000344

Published Jun 4, 2018

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been remove…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000340

Published Jun 4, 2018

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13098

Published Dec 13, 2017

BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any T…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-2427

Published Apr 18, 2016

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1