VYPR
Vendor

Gnupg

Products
17
CVEs
72
Across products
88
Status
Private

Products

17

Recent CVEs

72
View all 72 CVEs →
  • CVE-2022-3515CriJan 12, 2023
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.

  • CVE-2022-47629CriDec 20, 2022
    risk 0.64cvss 9.8epss 0.02

    Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.

  • CVE-2020-24972HigAug 29, 2020
    risk 0.58cvss 8.8epss 0.05

    The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an…

  • CVE-2018-1000858HigDec 20, 2018
    risk 0.57cvss 8.8epss 0.01

    GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in…

  • CVE-2010-2547HigAug 5, 2010
    risk 0.53cvss 8.1epss 0.05

    Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled…

  • CVE-2021-3345HigJan 29, 2021
    risk 0.51cvss 7.8epss 0.01

    _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.

  • CVE-2020-25125HigSep 3, 2020
    risk 0.51cvss 7.8epss 0.01

    GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x…

  • CVE-2021-33560HigJun 8, 2021
    risk 0.49cvss 7.5epss 0.02

    Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.

  • CVE-2019-14855HigMar 20, 2020
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.

  • CVE-2019-13050HigJun 29, 2019
    risk 0.49cvss 7.5epss 0.03

    Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent…

  • CVE-2018-12020HigJun 8, 2018
    risk 0.49cvss 7.5epss 0.09

    mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" option. For example, the OpenPGP…

  • CVE-2018-9234HigApr 4, 2018
    risk 0.49cvss 7.5epss 0.02

    GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.

  • CVE-2018-6829HigFeb 7, 2018
    risk 0.49cvss 7.5epss 0.02

    cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack).…

  • CVE-2017-0379HigAug 29, 2017
    risk 0.49cvss 7.5epss 0.04

    Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, related to cipher/ecc.c and mpi/ec.c.

  • CVE-2016-4579HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.03

    Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."

  • CVE-2016-4574HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.03

    Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for…

  • CVE-2016-4356HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.03

    The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.

  • CVE-2016-4355HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.02

    Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

  • CVE-2016-4354HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.02

    ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.

  • CVE-2016-4353HigJun 13, 2016
    risk 0.49cvss 7.5epss 0.02

    ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.