Show filters
29 Total Results
Displaying 21-29 of 29
Sort by:
Attacker Value
Unknown

CVE-2016-2850

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7827

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
0
Attacker Value
Unknown

CVE-2015-5727

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
0
Attacker Value
Unknown

CVE-2014-9742

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.
0
Attacker Value
Unknown

CVE-2016-2194

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.
0
Attacker Value
Unknown

CVE-2015-5726

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
0
Attacker Value
Unknown

CVE-2016-2849

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
0
Attacker Value
Unknown

CVE-2016-2195

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-2196

Disclosure Date: May 13, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.
0