VYPR

Bouncy Castle

by Legion of the Bouncy Castle Inc.

CVEs (3)

  • CVE-2017-13098HigDec 13, 2017
    risk 0.50cvss 7.5epss 0.68

    BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a…

  • CVE-2015-6644LowJan 6, 2016
    risk 0.21cvss 3.3epss 0.00

    Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.

  • CVE-2018-5382Apr 16, 2018
    risk 0.00cvss epss 0.00

    The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated…