CVE-2016-2850
- EPSS 0.43%
- Published 13.05.2016 14:59:11
- Last modified 12.04.2025 10:46:40
Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
CVE-2016-2849
- EPSS 0.58%
- Published 13.05.2016 14:59:10
- Last modified 12.04.2025 10:46:40
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
- EPSS 2.57%
- Published 13.05.2016 14:59:09
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.
- EPSS 6.11%
- Published 13.05.2016 14:59:08
- Last modified 12.04.2025 10:46:40
Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.
CVE-2016-2194
- EPSS 1.69%
- Published 13.05.2016 14:59:07
- Last modified 12.04.2025 10:46:40
The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.
CVE-2015-7827
- EPSS 0.44%
- Published 13.05.2016 14:59:03
- Last modified 12.04.2025 10:46:40
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
CVE-2015-5727
- EPSS 0.61%
- Published 13.05.2016 14:59:02
- Last modified 12.04.2025 10:46:40
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
CVE-2015-5726
- EPSS 0.87%
- Published 13.05.2016 14:59:01
- Last modified 12.04.2025 10:46:40
The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.
CVE-2014-9742
- EPSS 0.28%
- Published 13.05.2016 14:59:00
- Last modified 12.04.2025 10:46:40
The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.