Search CVE reports


Toggle filters

31 – 36 of 36 results


CVE-2016-2195

Medium priority

Some fixes available 1 of 3

Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based...

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2016-2194

Medium priority

Some fixes available 1 of 3

The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2015-7827

Medium priority

Some fixes available 1 of 6

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10 Not in release Not in release Not in release Not in release Not affected
Show less packages

CVE-2015-5727

Medium priority

Some fixes available 1 of 2

The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2015-5726

Medium priority

Some fixes available 1 of 2

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages

CVE-2014-9742

Medium priority

Some fixes available 1 of 2

The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.

1 affected package

botan1.10

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
botan1.10
Show less packages