2.1

CVE-2010-3074

SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.

Data is provided by the National Vulnerability Database (NVD)
Arg0Encfs Version <= 1.6.0
Arg0Encfs Version1.4.0
Arg0Encfs Version1.4.1
Arg0Encfs Version1.4.1.1
Arg0Encfs Version1.4.2
Arg0Encfs Version1.5.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.07% 0.189
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N