Show filters
41 Total Results
Displaying 11-20 of 41
Sort by:
Attacker Value
Unknown

CVE-2019-9153

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
Improper Verification of a Cryptographic Signature in OpenPGP.js <=4.1.2 allows an attacker to forge signed messages by replacing its signatures with a "standalone" or "timestamp" signature.
0
Attacker Value
Unknown

CVE-2019-9155

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
A cryptographic issue in OpenPGP.js <=4.2.0 allows an attacker who is able provide forged messages and gain feedback about whether decryption of these messages succeeded to conduct an invalid curve attack in order to gain the victim's ECDH private key.
0
Attacker Value
Unknown

CVE-2019-8338

Disclosure Date: May 16, 2019 (last updated November 27, 2024)
The signature verification routine in the Airmail GPG-PGP Plugin, versions 1.0 (9) and earlier, does not verify the status of the signature at all, which allows remote attackers to spoof arbitrary email signatures by crafting a signed email with an invalid signature. Also, it does not verify the validity of the signing key, which allows remote attackers to spoof arbitrary email signatures by crafting a key with a fake user ID (email address) and injecting it into the user's keyring.
0
Attacker Value
Unknown

CVE-2018-16203

Disclosure Date: January 09, 2019 (last updated November 27, 2024)
PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgreSQL database via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-8013

Disclosure Date: July 25, 2017 (last updated November 26, 2024)
s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is used as an authentication mechanism via a crafted symmetrically encrypted PGP message.
0
Attacker Value
Unknown

CVE-2016-4021

Disclosure Date: May 26, 2016 (last updated November 25, 2024)
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
0
Attacker Value
Unknown

CVE-2014-7288

Disclosure Date: February 01, 2015 (last updated October 05, 2023)
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.
0
Attacker Value
Unknown

CVE-2014-7287

Disclosure Date: February 01, 2015 (last updated October 05, 2023)
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.
0
Attacker Value
Unknown

CVE-2014-3436

Disclosure Date: August 22, 2014 (last updated October 05, 2023)
Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted encrypted e-mail message that decompresses to a larger size.
0
Attacker Value
Unknown

CVE-2014-3431

Disclosure Date: June 21, 2014 (last updated October 05, 2023)
Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors.
0