Libtom maintains a focused set of open-source cryptographic and mathematical libraries—chiefly LibTomCrypt and LibTomMath—that are embedded in security-sensitive applications across diverse platforms, giving vulnerabilities in these components broad downstream impact despite the narrow vendor footprint. The recurring weakness classes affecting this vendor center on cryptographic implementation details: sensitive-information exposure, input validation gaps, integer overflows, and out-of-bounds reads that reflect the low-level nature of parsing and arithmetic operations in cryptographic code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libtom over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36328CRITICAL Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial | Sep 1, 2023 | 9.8 | 29 | NO | NO |
CVE-2019-17362CRITICAL In LibTomCrypt through 1.18.2, the der_decode_utf8_string function (in der_decode_utf8_string.c) does not properly detect certain invalid UTF-8 sequences. This allows context-depen | Oct 9, 2019 | 9.1 | 29 | NO | NO |
CVE-2016-6129HIGH The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data le | Feb 13, 2017 | 7.5 | 24 | NO | NO |
CVE-2018-12437MEDIUM LibTomCrypt through 1.18.1 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attack | Jun 15, 2018 | 4.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libtom.
Media articles that mention a CVE ID that affects a product developed by Libtom — matched by CVE ID, not by vendor name.