Search CVE reports


Toggle filters

11 – 20 of 38 results


CVE-2024-29857

Medium priority

Some fixes available 4 of 8

An issue was discovered in ECCurve.java and ECCurve.cs in Bouncy Castle Java (BC Java) before 1.78, BC Java LTS before 2.73.6, BC-FJA before 1.0.2.5, and BC C# .Net before 2.3.1. Importing an EC certificate with crafted F2m...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-34447

Medium priority

Some fixes available 3 of 6

An issue was discovered in the Bouncy Castle Crypto Package For Java before BC TLS Java 1.0.19 (ships with BC Java 1.78, BC Java (LTS) 2.73.6) and before BC FIPS TLS Java 1.0.19. When endpoint identification is enabled in the...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Fixed Fixed Fixed Not affected
Show less packages

CVE-2023-33202

Medium priority
Vulnerable

Bouncy Castle for Java before 1.73 contains a potential Denial of Service (DoS) issue within the Bouncy Castle org.bouncycastle.openssl.PEMParser class. This class parses OpenSSL PEM encoded streams containing X.509 certificates,...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2023-33201

Medium priority

Some fixes available 4 of 9

Bouncy Castle For Java before 1.74 is affected by an LDAP injection vulnerability. The vulnerability only affects applications that use an LDAP CertStore from Bouncy Castle to validate X.509 certificates. During the certificate...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Fixed Fixed Fixed
Show less packages

CVE-2022-45146

Medium priority
Ignored

An issue was discovered in the FIPS Java API of Bouncy Castle BC-FJA before 1.0.2.4. Changes to the JVM garbage collector in Java 13 and later trigger an issue in the BC-FJA FIPS modules where it is possible for temporary...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-15522

Medium priority
Ignored

Bouncy Castle BC Java before 1.66, BC C# .NET before 1.8.7, BC-FJA before 1.0.1.2, 1.0.2.1, and BC-FNA before 1.0.1.1 have a timing issue within the EC math library that can expose information about the private key when...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Ignored Ignored
Show less packages

CVE-2020-28052

Medium priority
Ignored

An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Not affected Not affected
Show less packages

CVE-2020-26939

Low priority
Not affected

In Legion of the Bouncy Castle BC before 1.61 and BC-FJA before 1.0.1.2, attackers can obtain sensitive information about a private exponent because of Observable Differences in Behavior to Error Inputs. This occurs...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Not affected Ignored
Show less packages

CVE-2019-17359

Medium priority
Not affected

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected
Show less packages

CVE-2018-1000613

Medium priority
Vulnerable

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability...

1 affected package

bouncycastle

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bouncycastle Not affected Not affected Not affected Vulnerable
Show less packages