Search CVE reports


Toggle filters

31 – 36 of 36 results


CVE-2016-2195

Medium priority

Some fixes available 1 of 3

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based...

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2016-2194

Medium priority

Some fixes available 1 of 3

The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2015-7827

Medium priority

Some fixes available 1 of 6

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10 Not in release Not in release Not in release Not affected
Show less packages

CVE-2015-5727

Medium priority

Some fixes available 1 of 2

The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2015-5726

Medium priority

Some fixes available 1 of 2

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2014-9742

Medium priority

Some fixes available 1 of 2

The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.

1 affected package

botan1.10

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages