Dlitz maintains PyCrypto, a Python cryptographic library with a concentrated but prominent footprint in legacy systems and educational contexts, where its narrow scope belies its broad downstream reach through application dependencies. The vulnerability profile centers on memory-safety and cryptographic-strength issues, including buffer-boundary violations and inadequate encryption implementations, which are characteristic weaknesses in native cryptographic code that has matured without systematic memory-safe redesign. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dlitz over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-7459CRITICAL Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrate | Feb 15, 2017 | 9.8 | 35 | NO | NO |
CVE-2018-6594HIGH lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data ( | Feb 3, 2018 | 7.5 | 25 | NO | NO |
CVE-2013-1445MEDIUM The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which ma | Oct 26, 2013 | 4.3 | 18 | NO | NO |
CVE-2012-2417MEDIUM PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it ea | Jun 17, 2012 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dlitz.
Media articles that mention a CVE ID that affects a product developed by Dlitz — matched by CVE ID, not by vendor name.