Show filters
108 Total Results
Displaying 31-40 of 108
Sort by:
Attacker Value
Unknown
CVE-2023-50980
Disclosure Date: December 18, 2023 (last updated December 28, 2023)
gf2n.cpp in Crypto++ (aka cryptopp) through 8.9.0 allows attackers to cause a denial of service (application crash) via DER public-key data for an F(2^m) curve, if the degree of each term in the polynomial is not strictly decreasing.
0
Attacker Value
Unknown
CVE-2023-50979
Disclosure Date: December 18, 2023 (last updated December 28, 2023)
Crypto++ (aka cryptopp) through 8.9.0 has a Marvin side channel during decryption with PKCS#1 v1.5 padding.
0
Attacker Value
Unknown
CVE-2023-49150
Disclosure Date: December 14, 2023 (last updated December 20, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CurrencyRate.Today Crypto Converter Widget allows Stored XSS.This issue affects Crypto Converter Widget: from n/a through 1.8.1.
0
Attacker Value
Unknown
CVE-2023-46233
Disclosure Date: October 25, 2023 (last updated November 07, 2023)
crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because it both defaults to SHA1, a cryptographic hash algorithm considered insecure since at least 2005, and defaults to one single iteration, a 'strength' or 'difficulty' value specified at 1,000 when specified in 1993. PBKDF2 relies on iteration count as a countermeasure to preimage and collision attacks. If used to protect passwords, the impact is high. If used to generate signatures, the impact is high. Version 4.2.0 contains a patch for this issue. As a workaround, configure crypto-js to use SHA256 with at least 250,000 iterations.
0
Attacker Value
Unknown
CVE-2023-44273
Disclosure Date: September 28, 2023 (last updated October 08, 2023)
Consensys gnark-crypto through 0.11.2 allows Signature Malleability. This occurs because deserialisation of EdDSA and ECDSA signatures does not ensure that the data is in a certain interval.
0
Attacker Value
Unknown
CVE-2023-37759
Disclosure Date: September 08, 2023 (last updated October 08, 2023)
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
0
Attacker Value
Unknown
CVE-2022-48570
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Crypto++ through 8.4 contains a timing side channel in ECDSA signature generation. Function FixedSizeAllocatorWithCleanup could write to memory outside of the allocation if the allocated memory was not 16-byte aligned. NOTE: this issue exists because the CVE-2019-14318 fix was intentionally removed for functionality reasons.
0
Attacker Value
Unknown
CVE-2023-3249
Disclosure Date: June 30, 2023 (last updated November 09, 2023)
The Web3 – Crypto wallet Login & NFT token gating plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.6.0. This is due to incorrect authentication checking in the 'hidden_form_data' function. This makes it possible for authenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.
0
Attacker Value
Unknown
CVE-2020-36732
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
The crypto-js package before 3.2.1 for Node.js generates random numbers by concatenating the string "0." with an integer, which makes the output more predictable than necessary.
0
Attacker Value
Unknown
CVE-2023-28725
Disclosure Date: March 22, 2023 (last updated October 08, 2023)
General Bytes Crypto Application Server (CAS) 20230120, as distributed with General Bytes BATM devices, allows remote attackers to execute arbitrary Java code by uploading a Java application to the /batm/app/admin/standalone/deployments directory, aka BATM-4780, as exploited in the wild in March 2023. This is fixed in 20221118.48 and 20230120.44.
0