Vulnerabilities > Briarproject
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-24 | CVE-2023-33980 | Resource Exhaustion vulnerability in Briarproject Briar Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a contact. | 7.5 |
2023-05-24 | CVE-2023-33981 | Improper Validation of Integrity Check Value vulnerability in Briarproject Briar Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimate message displayed alongside the spoofed one. | 6.5 |
2023-05-24 | CVE-2023-33982 | Inadequate Encryption Strength vulnerability in Briarproject Briar Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts. | 5.9 |
2023-05-24 | CVE-2023-33983 | Missing Authorization vulnerability in Briarproject Briar The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. | 7.4 |