Skip to main content

Vendor/product archive

cryptopp / crypto++ CVEs

Beta · best-effort

12 CVEs tagged to cryptopp / crypto++0 Critical, 6 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2023-50981

Published Dec 18, 2023

ModularSquareRoot in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (infinite loop) via crafted DER public-key data associated with squared od…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50980

Published Dec 18, 2023

gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50979

Published Dec 18, 2023

Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-48570

Published Aug 22, 2023

Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43398

Published Nov 4, 2021

Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation between execution time and private key length, which may cause…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40530

Published Sep 6, 2021

The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of th…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14318

Published Jul 30, 2019

Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousa…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-9434

Published Jun 5, 2017

Crypto++ (aka cryptopp) through 5.6.5 contains an out-of-bounds read vulnerability in zinflate.cpp in the Inflator filter.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3995

Published Feb 13, 2017

The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka cryptopp) before 5.6.4 may be optimized out by the compile…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9939

Published Jan 30, 2017

Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 ob…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7544

Published Jan 30, 2017

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7420

Published Sep 16, 2016

Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1