CSIRO's vulnerability footprint centers on the Multi-Protocol SPDZ secure multiparty computation framework, a specialized cryptographic software library deployed in research and privacy-preserving application contexts. The durable signal reflects memory-safety weaknesses endemic to native implementations: buffer overflows, out-of-bounds reads, and classic stack-based copy vulnerabilities that arise from the framework's low-level protocol handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Csiro over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33782HIGH MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function OTExtensionWithMatrix::extend in /OT/OTExtensionWithMatrix.cpp. This vulnerability allows attackers to ca | May 7, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-33781HIGH MP-SPDZ v0.3.8 was discovered to contain a stack overflow via the function octetStream::get_bytes in /Tools/octetStream.cpp. This vulnerability allows attackers to cause a Denial o | May 7, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-33780MEDIUM MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::copyOut at /Tools/SilentPprf.cpp. This vulnerability allows attackers to cause a Denia | May 7, 2024 | 6.5 | 19 | NO | NO |
CVE-2024-33783MEDIUM MP-SPDZ v0.3.8 was discovered to contain a segmentation violation via the function osuCrypto::SilentMultiPprfReceiver::expand in /Tools/SilentPprf.cpp. This vulnerability allows at | May 7, 2024 | 6.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Csiro.
Media articles that mention a CVE ID that affects a product developed by Csiro — matched by CVE ID, not by vendor name.