Mcrypt is a focused cryptographic library that provides encryption functions to applications across Unix and Linux systems, with its exposure centered on the single libmcrypt library product. The observed vulnerability profile reflects the memory-handling demands of a C-based cryptographic implementation, with recurring issues in buffer boundary checks, format string handling, and implementation-specific weaknesses that are typical of legacy low-level security libraries. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mcrypt over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4409MEDIUM Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to execute arbitrary code via an encrypted | Nov 21, 2012 | 6.8 | 38 | NO | YES |
CVE-2012-4527MEDIUM Stack-based buffer overflow in mcrypt 2.6.8 and earlier allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long fi | Nov 21, 2012 | 6.8 | 25 | NO | NO |
CVE-2012-4426MEDIUM Multiple format string vulnerabilities in mcrypt 2.6.8 and earlier might allow user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary cod | Nov 21, 2012 | 6.8 | 23 | NO | NO |
CVE-2003-0031HIGH Multiple buffer overflows in libmcrypt before 2.5.5 allow attackers to cause a denial of service (crash). | Jan 17, 2003 | 7.5 | 19 | NO | NO |
CVE-2003-0032MEDIUM Memory leak in libmcrypt before 2.5.5 allows attackers to cause a denial of service (memory exhaustion) via a large number of requests to the application, which causes libmcrypt to | Jan 17, 2003 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mcrypt.
Media articles that mention a CVE ID that affects a product developed by Mcrypt — matched by CVE ID, not by vendor name.