Gnupg
by Gnupg
Source repositories
CVEs (45)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-0366 | 0.00 | — | 0.03 | May 2, 2005 | The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or… | |||
| CVE-2003-0971 | 0.00 | — | 0.03 | Dec 15, 2003 | GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature. | |||
| CVE-2001-0072 | 0.00 | — | 0.02 | Feb 12, 2001 | gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust. | |||
| CVE-2001-0071 | 0.00 | — | 0.00 | Feb 12, 2001 | gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection. | |||
| CVE-2000-0974 | 0.00 | — | 0.03 | Dec 19, 2000 | GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection. |
- CVE-2005-0366May 2, 2005risk 0.00cvss —epss 0.03
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or…
- CVE-2003-0971Dec 15, 2003risk 0.00cvss —epss 0.03
GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
- CVE-2001-0072Feb 12, 2001risk 0.00cvss —epss 0.02
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
- CVE-2001-0071Feb 12, 2001risk 0.00cvss —epss 0.00
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.
- CVE-2000-0974Dec 19, 2000risk 0.00cvss —epss 0.03
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
Page 3 of 3