Skip to main content

Vendor/product archive

briarproject / briar CVEs

Beta · best-effort

4 CVEs tagged to briarproject / briar0 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2023-33983

Published May 24, 2023

The Introduction Client in Briar through 1.5.3 does not implement out-of-band verification for the public keys of introducees. An introducer can launch man-in-the-middle attacks a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33982

Published May 24, 2023

Bramble Handshake Protocol (BHP) in Briar before 1.5.3 is not forward secure: eavesdroppers can decrypt network traffic between two accounts if they later compromise both accounts…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33981

Published May 24, 2023

Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private group, but each spoofed message would need to be an exact duplicate of a legitimat…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33980

Published May 24, 2023

Bramble Synchronisation Protocol (BSP) in Briar before 1.4.22 allows attackers to cause a denial of service (repeated application crashes) via a series of long messages to a conta…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1