VYPR

Gnupg

by Gnupg

Source repositories

CVEs (45)

  • CVE-2005-0366May 2, 2005
    risk 0.00cvss epss 0.03

    The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or…

  • CVE-2003-0971Dec 15, 2003
    risk 0.00cvss epss 0.03

    GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.

  • CVE-2001-0072Feb 12, 2001
    risk 0.00cvss epss 0.02

    gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.

  • CVE-2001-0071Feb 12, 2001
    risk 0.00cvss epss 0.00

    gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.

  • CVE-2000-0974Dec 19, 2000
    risk 0.00cvss epss 0.03

    GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.

Page 3 of 3