Bc Java

Vendor:

First CVE: Mar 30, 2009 · Active for 17 years

19
Total CVEs
More Total CVEs than 93% of tracked products
2.4
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bc Java over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2009
17 years ago
Most Recent CVE
Jul 5, 2023
1,115 days ago

CVE Severity & Scoring

Bc Java19 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (10.5%)
Network15 (78.9%)
Unknown2 (10.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (52.6%)
High7 (36.8%)
Unknown2 (10.5%)
User Interaction
None16 (84.2%)
Unknown2 (10.5%)
Required1 (5.3%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None16 (84.2%)
Unknown2 (10.5%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TL
Dec 13, 20175.939NOYES
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Cl
Jul 9, 20189.832NONO
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, all
Dec 18, 20208.129NONO
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is f
Oct 8, 20197.529NONO
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-l
Jun 5, 20187.526NONO
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "
Mar 30, 200910.026NONO
In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed
Jun 4, 20187.425NONO
In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not
Jun 4, 20187.525NONO
In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed
Jun 4, 20187.424NONO
In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the
Jun 4, 20187.524NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
5.3% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Bc Java

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6618.17.1%00
1.6518.17.1%00
1.6317.58.9%00
1.5415.50.4%00
1.4714.03.0%00
1.4614.03.0%00
1.4514.03.0%00
1.4414.03.0%00
1.4314.03.0%00
1.4214.03.0%00
1.4114.03.0%00
1.4014.03.0%00
1.3914.03.0%00
1.3814.03.0%00
1.3714.03.0%00
1.3627.02.7%00
1.3527.02.7%00
1.3427.02.7%00
1.3327.02.7%00
1.3227.02.7%00