timlegge crypt::nacl::sodium の CVE(2 件)

CVE 件数: 2 CPE versions: View versions table

概要

本ページは timlegge crypt::nacl::sodium に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 12 / 2 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-30909 Crypt::NaCl::Sodium versions through 2.002 for Perl has potential integer overflows. bin2hex, encrypt, aes256gcm_encrypt_afternm and seal functions do not check that output size will be less than SIZE_MAX, which could lead to integer wraparound causing an undersized output buffer. Encountering this issue is unlikely as the message length would need to be very large. For bin2hex() the bin_len would have to be > SIZE_MAX / 2 For encrypt() the msg_len would need to be > SIZE_MAX - 16U For aes256 9b29abf9-4ab0-4765-b253-1875cd9b441e 9.8 0.03% 2026-03-08 2026-03-18
CVE-2026-2588 Crypt::NaCl::Sodium versions through 2.001 for Perl has an integer overflow flaw on 32-bit systems. Sodium.xs casts a STRLEN (size_t) to unsigned long long when passing a length pointer to libsodium functions. On 32-bit systems size_t is typically 32-bits while an unsigned long long is at least 64-bits. 9b29abf9-4ab0-4765-b253-1875cd9b441e 9.1 0.05% 2026-02-23 2026-03-04
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence