Aescrypt is a file-encryption utility with a narrow product footprint centered on its core AES encryption tool, where observed vulnerabilities cluster around buffer-handling defects such as classic buffer overflows and improper input validation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aescrypt over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7463HIGH The aescrypt gem 1.0.0 for Ruby does not randomize the CBC IV for use with the AESCrypt.encrypt and AESCrypt.decrypt functions, which allows attackers to defeat cryptographic prote | Apr 19, 2017 | 7.5 | 25 | NO | NO |
CVE-2022-35928MEDIUM AES Crypt is a file encryption software for multiple platforms. AES Crypt for Linux built using the source on GitHub and having the version number 3.11 has a vulnerability with res | Aug 3, 2022 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aescrypt.
Media articles that mention a CVE ID that affects a product developed by Aescrypt — matched by CVE ID, not by vendor name.