VendorsIndutnyelliptic6.5.6
Vulnerabilities

Indutny Elliptic 6.5.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-42460
In the Elliptic package 6.5.6 for Node.js, ECDSA signature malleability occurs because there is a missing check for whether the leading bit of r and s is zero.
Published 2024-08-02 · Modified
5.3EPSS 0.005
CVE-2024-42459
In the Elliptic package 6.5.6 for Node.js, EDDSA signature malleability occurs because there is a missing signature length check, and thus zero-valued bytes can be removed or appended.
Published 2024-08-02 · Modified
5.3EPSS 0.003