Show filters
79 Total Results
Displaying 71-79 of 79
Sort by:
Attacker Value
Unknown
CVE-2016-7544
Disclosure Date: January 30, 2017 (last updated November 25, 2024)
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.
0
Attacker Value
Unknown
CVE-2016-9939
Disclosure Date: January 30, 2017 (last updated November 08, 2023)
Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on the length field of the ASN.1 object. If there is not enough content octets in the ASN.1 object, then the function will fail and the memory block will be zeroed even if its unused. There is a noticeable delay during the wipe for a large allocation.
0
Attacker Value
Unknown
CVE-2016-7420
Disclosure Date: September 16, 2016 (last updated November 25, 2024)
Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.
0
Attacker Value
Unknown
CVE-2015-2141
Disclosure Date: July 01, 2015 (last updated October 05, 2023)
The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Williams digital signature algorithm, which allows remote attackers to obtain private keys via a timing attack.
0
Attacker Value
Unknown
CVE-2012-4455
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki 2.4.1 allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) LCK..opencryptoki or (2) LCK..opencryptoki_stdll file in /var/lock/.
0
Attacker Value
Unknown
CVE-2012-4454
Disclosure Date: October 10, 2012 (last updated October 05, 2023)
openCryptoki before 2.4.1, when using spinlocks, allows local users to create or set world-writable permissions on arbitrary files via a symlink attack on the (1) .pkapi_xpk or (2) .pkcs11spinloc file in /tmp.
0
Attacker Value
Unknown
CVE-2009-0544
Disclosure Date: February 12, 2009 (last updated October 04, 2023)
Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.
0
Attacker Value
Unknown
CVE-2006-6145
Disclosure Date: November 28, 2006 (last updated October 04, 2023)
CRYPTOCard CRYPTO-Server before 6.4.56 stores LDAP credentials in plaintext in UninstallerData\installvariables.properties, which has insecure permissions and allows local users to obtain the credentials. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2000-0275
Disclosure Date: April 10, 2000 (last updated February 22, 2025)
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with access to the .PDB file to generate valid PT-1 tokens after cracking the PIN.
0