bitwiseshiftleft CVE 脆弱性と CVE 一覧(1)

製品(CPE): — CVE 件数: 1

bitwiseshiftleft 脆弱性概要

This page aggregates publicly disclosed CVE and security risk information related to bitwiseshiftleft, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

脆弱性分布の推移(直近24か月)

表示中 11 / 1 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2026-4258 All versions of the package sjcl are vulnerable to Improper Verification of Cryptographic Signature due to missing point-on-curve validation in sjcl.ecc.basicKey.publicKey(). An attacker can recover a victim's ECDH private key by sending crafted off-curve public keys and observing ECDH outputs. The dhJavaEc() function directly returns the raw x-coordinate of the scalar multiplication result (no hashing), providing a plaintext oracle without requiring any decryption feedback. [email protected] 7.7 0.02% 2026-03-17 2026-06-03
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence