The Pbc Project maintains a cryptographic library focused on pairing-based cryptography that, despite a narrow product scope, holds prominence in specialized security and cryptographic applications where its primitives are embedded. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and recur through memory-safety and state-management weakness classes—including buffer-boundary violations, out-of-bounds reads, NULL-pointer dereferences, unchecked return values, and use-after-free conditions—that are characteristic of native cryptographic implementations handling untrusted inputs. Defenders should monitor this vendor's releases closely given the severity profile and the likelihood that flaws in foundational cryptographic code propagate across downstream applications; live exploitation and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pbc Project over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12918CRITICAL In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c. | Jun 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12917CRITICAL In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c. | Jun 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12916CRITICAL In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c. | Jun 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-12915CRITICAL In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c. | Jun 27, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14744CRITICAL An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A use-after-free can occur in _pbcM_sp_query in map.c. | Jul 30, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14743HIGH An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in wiretype_decode in context.c. | Jul 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14742HIGH An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c during a memcpy. | Jul 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14740HIGH An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in set_field_one in bootstrap.c while making a query. | Jul 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14739HIGH An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_pattern_set_default in pattern.c. | Jul 30, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14738HIGH An issue was discovered in libpbc.a in cloudwu PBC through 2017-03-02. A SEGV can occur in pbc_rmessage_message in rmessage.c. | Jul 30, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pbc Project.
Media articles that mention a CVE ID that affects a product developed by Pbc Project — matched by CVE ID, not by vendor name.