Relic Project's vulnerability footprint centers on the Relic cryptocurrency and blockchain software, with observed weaknesses clustering around memory-safety and cryptographic implementation concerns, including integer overflows, buffer overflows, injection flaws, and use of broken cryptographic algorithms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Relic Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36327CRITICAL Integer Overflow vulnerability in RELIC before commit 421f2e91cf2ba42473d4d54daf24e295679e290e, allows attackers to execute arbitrary code and cause a denial of service in pos argu | Sep 1, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-36326CRITICAL Integer Overflow vulnerability in RELIC before commit 34580d840469361ba9b5f001361cad659687b9ab, allows attackers to execute arbitrary code, cause a denial of service, and escalate | Sep 1, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-51939HIGH An issue in the cp_bbs_sig function in relic/src/cp/relic_cp_bbs.c of Relic relic-toolkit 0.6.0 allows a remote attacker to obtain sensitive information and escalate privileges via | Feb 1, 2024 | 8.8 | 24 | NO | NO |
CVE-2020-36316MEDIUM In RELIC before 2021-04-03, there is a buffer overflow in PKCS#1 v1.5 signature verification because garbage bytes can be present. | Apr 7, 2021 | 5.5 | 19 | NO | NO |
CVE-2020-36315MEDIUM In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes) are inadequate. NOTE: this requires that | Apr 7, 2021 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Relic Project.
Media articles that mention a CVE ID that affects a product developed by Relic Project — matched by CVE ID, not by vendor name.