🧬 Known OSS vulnerabilities — OSV-Scannerⓘ3 found · 1 serious
Your dependencies cross-checked against the OSV vulnerability database.
SeriousPYSEC-2017-94 Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv pa
A package you depend on has a known security hole (CVE-2013-7459). Fix: Update that package to its patched version.
Worth fixingPYSEC-2013-29 The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for co
A package you depend on has a known security hole (CVE-2013-1445). Fix: Update that package to its patched version.
Worth fixingPYSEC-2018-97 lib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not ha
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.