Vulnerabilities > Botan Project > High

DATE CVE VULNERABILITY TITLE RISK
2023-11-03 CVE-2017-7252 Cleartext Transmission of Sensitive Information vulnerability in Botan Project Botan
bcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
network
low complexity
botan-project CWE-319
7.5
2021-02-22 CVE-2021-24115 Unspecified vulnerability in Botan Project Botan
In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).
network
low complexity
botan-project
7.5
2018-04-02 CVE-2018-9127 Improper Certificate Validation vulnerability in Botan Project Botan 2.2.0/2.3.0/2.4.0
Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should not match.
network
low complexity
botan-project CWE-295
7.5
2017-05-24 CVE-2017-2801 Out-of-bounds Read vulnerability in Botan Project Botan 2.0.1
A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string comparisons which could lead to certificate verification issues and abuse.
network
low complexity
botan-project CWE-125
7.5
2017-04-10 CVE-2016-6878 Improper Input Validation vulnerability in Botan Project Botan
The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via vectors related to undefined behavior, as demonstrated on 32-bit ARM systems compiled by Clang.
network
low complexity
botan-project CWE-20
7.5
2017-04-10 CVE-2015-7826 Improper Certificate Validation vulnerability in Botan Project Botan
botan 1.11.x before 1.11.22 improperly handles wildcard matching against hostnames, which might allow remote attackers to have unspecified impact via a valid X.509 certificate, as demonstrated by accepting *.example.com as a match for bar.foo.example.com.
network
low complexity
botan-project CWE-295
7.5
2017-04-10 CVE-2015-7825 Unspecified vulnerability in Botan Project Botan
botan before 1.11.22 improperly validates certificate paths, which allows remote attackers to cause a denial of service (infinite loop and memory consumption) via a certificate with a loop in the certificate chain.
network
low complexity
botan-project
7.8
2016-05-13 CVE-2015-5727 Resource Management Errors vulnerability in multiple products
The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.
network
low complexity
botan-project debian CWE-399
7.8