Pgp vulnerabilities

9 known vulnerabilities affecting pgp/pgp.

Total CVEs
9
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2LOW4

Vulnerabilities

Page 1 of 1
CVE-2026-21895LOWCVSS 2.7≥ 0.16.0-alpha.0, < 0.19.02026-02-13
CVE-2026-21895 [LOW] CWE-703 rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895 rPGP vulnerable to parser crash on crafted RSA secret key packets through CVE-2026-21895 ### Summary It was possible to trigger an unhandled edge case in the Rust Crypto rsa crate through rPGP packet parsing functionality, and crash the process that runs rPGP. This problem has been patched in a new rsa version. The new release of rPGP ensures a patched version of the rsa crate i
ghsaosv
CVE-2024-53857HIGH≥ 0, < 0.14.22024-12-05
CVE-2024-53857 [HIGH] CWE-770 rPGP Potential Resource Exhaustion when handling Untrusted Messages rPGP Potential Resource Exhaustion when handling Untrusted Messages During a security audit, [Radically Open Security](https://www.radicallyopensecurity.com/) discovered two vulnerabilities which allow attackers to trigger resource exhaustion vulnerabilities in `rpgp` by providing crafted messages. This affects general message parsing and decryption with symmetric keys. ### Impact Affected `rpgp`
ghsaosv
CVE-2024-53856HIGH≥ 0, < 0.14.12024-12-05
CVE-2024-53856 [HIGH] CWE-130 rPGP Panics on Malformed Untrusted Input rPGP Panics on Malformed Untrusted Input During a security audit, [Radically Open Security](https://www.radicallyopensecurity.com/) discovered several reachable edge cases which allow an attacker to trigger `rpgp` crashes by providing crafted data. ### Impact When processing malformed input, `rpgp` can run into Rust panics which halt the program. This can happen in the following scenarios: * Parsing OpenPGP messages from b
ghsaosv
CVE-2002-1977LOWCVSS 2.1v7.0.4v7.12002-12-31
CVE-2002-1977 [LOW] CVE-2002-1977: Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Network Associates PGP 7.0.4 and 7.1 does not time out according to the value set in the "Passphrase Cache" option, which could allow attackers to open encrypted files without providing a passphrase.
nvd
CVE-2001-1016HIGHCVSS 7.5v5.0v6.0.22001-09-04
CVE-2001-1016 [HIGH] CVE-2001-1016: PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Busin PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by adding a second, invalid user ID to a key which
nvd
CVE-2001-0435MEDIUMCVSS 4.6v7.02001-07-02
CVE-2001-0435 [MEDIUM] CVE-2001-0435: The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key The split key mechanism used by PGP 7.0 allows a key share holder to obtain access to the entire key by setting the "Cache passphrase while logged on" option and capturing the passphrases of other share holders as they authenticate.
nvd
CVE-2001-0265LOWCVSS 2.1PoC≤ 7.0.3v52001-06-18
CVE-2001-0265 [LOW] CVE-2001-0265: ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary lo ASCII Armor parser in Windows PGP 7.0.3 and earlier allows attackers to create files in arbitrary locations via a malformed ASCII armored file.
nvd
CVE-2000-0678MEDIUMCVSS 5.0v5.5.3iv6.5.1i+1 more2000-10-20
CVE-2000-0678 [MEDIUM] CVE-2000-0678: PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in t PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
nvd
CVE-2000-0445LOWCVSS 2.1v5.0_linuxv5.0i+1 more2000-05-24
CVE-2000-0445 [LOW] CVE-2000-0445: The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-intera The pgpk command in PGP 5.x on Unix systems uses an insufficiently random data source for non-interactive key pair generation, which may produce predictable keys.
nvd