Ribose Limited is a cryptography and security software vendor whose disclosures center on its RNP library and related products for OpenPGP implementation and key management. The recurring vulnerability classes reflect the resource-handling and credential-protection demands of cryptographic software, including resource-consumption limits, cleartext credential storage, and insufficient credential protection mechanisms.
The number and severity of CVEs published that impact products developed by Ribose Limited over time
Of all the CVEs published by Ribose Limited as a CNA, 0.0% affect products that Ribose Limited develops as a vendor.
Of all the CVEs published that affect products developed by Ribose Limited, 0.0% are self-published by Ribose Limited as a CNA.
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33589HIGH Ribose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of the algorithm. | Apr 21, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-29480HIGH Ribose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use. | Apr 24, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-29479MEDIUM Ribose RNP before 0.16.3 may hang when the input is malformed. | Apr 24, 2023 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ribose Limited.
Media articles that mention a CVE ID that affects a product developed by Ribose Limited — matched by CVE ID, not by vendor name.