Nasa / CryptoLib
27 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-79954 | NASA CryptoLib 1.5.0 - TC receive path accepts Security Associations from the wrong GVCID | HIGH | 8.7 | Sep 18, 2026 |
| CVE-2026-22697 | CryptoLib Has Heap Buffer Overflow Vulnerability in KMC Base64 Decode Handling (KMC JSON base64ciphertext/base64cleartext) | HIGH | 7.5 | Jan 10, 2026 |
| CVE-2026-22027 | CryptoLib Vulnerable to Heap Buffer Overflow in MariaDB SA Hexstring Conversion | MEDIUM | 5.7 | Jan 10, 2026 |
| CVE-2026-22026 | CryptoLib Unbounded Memory Allocation in KMC HTTP Response Handler Allows Resource Exhaustion | HIGH | 8.2 | Jan 10, 2026 |
| CVE-2026-22025 | CryptoLib Memory Leak on HTTP Error Response in KMC Client | MEDIUM | 6.3 | Jan 10, 2026 |
| CVE-2026-22024 | CryptoLib Memory Leak in KMC Encrypt Function Leads to Resource Exhaustion | MEDIUM | 6.3 | Jan 10, 2026 |
| CVE-2026-22023 | CryptoLib Has Out-of-Bounds Read in KMC AEAD Encrypt Metadata Parsing via Flawed strtok Pattern | HIGH | 8.2 | Jan 10, 2026 |
| CVE-2026-21900 | CryptoLib Has Out-of-Bounds Read in KMC Encrypt Metadata Parsing via Flawed strtok Pattern | HIGH | 8.2 | Jan 10, 2026 |
| CVE-2026-21899 | CryptoLib has an out-of-bounds read and crash vulnerability when decoding an empty Base64url string | MEDIUM | 4.9 | Jan 10, 2026 |
| CVE-2026-21898 | CryptoLib Has Out-of-bounds Read in Crypto_AOS_ProcessSecurity | HIGH | 8.2 | Jan 10, 2026 |
| CVE-2026-21897 | CryptoLib Has Out-of-Bounds Write in Crypto_Config_Add_Gvcid_Managed_Parameters | HIGH | 7.3 | Jan 10, 2026 |
| CVE-2025-64096 | CryptoLib vulnerable to Stack Buffer Overflow in Crypto_Key_Update due to missing TLV length check | HIGH | 8.8 | Oct 30, 2025 |
| CVE-2025-59534 | CryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login() | HIGH | 7.8 | Sep 23, 2025 |
| CVE-2025-54878 | Heap Buffer Overflow in NASA CryptoLib 1.4.0 `Crypto_TC_Check_IV_Setup` | HIGH | 8.6 | Aug 11, 2025 |
| CVE-2025-46675 | In NASA CryptoLib before 1.3.2, the key state is not checked before use, potentially leading to spacecraft hijacking. | MEDIUM | 4.2 | Apr 27, 2025 |
| CVE-2025-46674 | NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracl… | CRITICAL | 9.9 | Apr 27, 2025 |
| CVE-2025-46673 | NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a bypass of the Space Data Link Security p… | CRITICAL | 9.9 | Apr 27, 2025 |
| CVE-2025-46672 | NASA CryptoLib before 1.3.2 does not check the OTAR crypto function returned status, potentially leading to spacecraft hijacking. | HIGH | 8.8 | Apr 27, 2025 |
| CVE-2025-30356 | Heap Buffer Overflow via Incomplete Length Check in `Crypto_TC_ApplySecurity` | CRITICAL | 9.3 | Apr 1, 2025 |
| CVE-2025-30216 | CryptoLib Has Heap Overflow in Crypto_TM_ProcessSecurity due to Unchecked Secondary Header Length | CRITICAL | 9.4 | Mar 25, 2025 |
| CVE-2025-29913 | CryptoLib's Crypto_TC_Prep_AAD Has Buffer Overflow Due to Integer Underflow | HIGH | 8.9 | Mar 17, 2025 |
| CVE-2025-29912 | CryptoLib Has Heap Buffer Overflow Due to Unsigned Integer Underflow in Crypto_TC_ProcessSecurity | HIGH | 8.9 | Mar 17, 2025 |
| CVE-2025-29911 | CryptoLib Has Heap Buffer Overflow in Crypto_AOS_ProcessSecurity Function | HIGH | 8.9 | Mar 17, 2025 |
| CVE-2025-29910 | CryptoLib's crypto_handle_incrementing_nontransmitted_counter Function has Memory Leak | MEDIUM | 5.5 | Mar 17, 2025 |
| CVE-2025-29909 | CryptoLib's Crypto_TC_ApplySecurity() Has a Heap Buffer Overflow Vulnerability | HIGH | 8.9 | Mar 17, 2025 |
Showing 1 to 25 of 27 CVEs