pkg:Maven/org.bouncycastle:bcprov-jdk15on
24 total CVEsCRITICAL1HIGH8MEDIUM12LOW1
✅ Check your installed version
All known vulnerabilities
- >= 1.57, < 1.60
- >= 1.65, < 1.67
- HIGH7.5CVE-2016-1000343In Bouncy Castle JCE Provider the DSA key pair generator generates a weak private key if used with default valuesfrom 0, < 1.56
- HIGH7.5CVE-2016-1000342In Bouncy Castle JCE Provider ECDSA does not fully validate ASN.1 encoding of signature on verificationfrom 0, < 1.56
- >= 1.51, < 1.56
- >= 1.38, < 1.56
- from 0, < 1.60
- HIGH7.4CVE-2016-1000344In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB modefrom 0, < 1.56
- HIGH7.4CVE-2016-1000352In Bouncy Castle JCE Provider the ECIES implementation allowed the use of ECB modefrom 0, < 1.56
- MEDIUM5.9CVE-2024-30171Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")from 0, < 1.78
- >= 1.61, < 1.78
- from 0, < 1.0.3
- MEDIUM5.9CVE-2016-1000345Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15from 0, < 1.56
- MEDIUM5.9CVE-2016-1000341Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15from 0, < 1.56
- from 0
- MEDIUM5.3CVE-2024-29857Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.from 0, < 1.78
- >= 1.49, <= 1.70
- from 0, < 1.61
- MEDIUM5.3CVE-2016-1000339Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15from 0, < 1.56
- from 0, < 1.66
- from 0, < 1.50
- LOW3.7CVE-2016-1000346In Bouncy Castle JCE Provider the other party DH public key is not fully validatedfrom 0, < 1.56
- from 0, < 1.48
- from 0, < 1.51