VulnSea

CWE-385

CVEs classified under CWE-385, newest first.

7 CVEsRSS

CVE-2026-84308Medium· 6.3
3w ago

phpseclib is a PHP secure communications library

phpseclib is a PHP secure communications library. Prior to 3.0.57 and 4.0.1, pure-PHP X25519 scalar multiplication in phpseclib/Math/PrimeField/Integer.php performs data-dependent conditional modular reductions in add() and subtract(). D…

Sunlitphpseclib · phpseclibEPSS 0.21%via NVD
CVE-2026-55785Low· 3.7
3w ago

free5GC is an open-source implementation of the 5G core network

free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAk…

Sunlitfree5gc · github.com/free5gc/ausfEPSS 0.28%via NVD
GHSA-5739-39v2-5754Medium
3mo ago

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

Sunlitweb-token · web-token/jwt-libraryvia GHSA
CVE-2026-6478Medium· 6.5
4mo ago

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supporte…

Sunlitpostgresql · postgresqlEPSS 0.56%via NVD
CVE-2026-5598High· 7.5
5mo ago

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc

Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, f…

TwilightLegion of the Bouncy Castle Inc. · coreEPSS 0.90%via NVD
CVE-2025-0306High· 7.4
1y ago

A vulnerability was found in Ruby

A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vu…

TwilightEPSS 0.65%via NVD
CVE-2023-3640High· 7.0PoC
3y ago

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data

A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-…

Midnightlinux · linux_kernelEPSS 0.76%via NVD
CWE-385 vulnerabilities (CVEs) · VulnSea