Known Vulnerabilities for products from Jahlives
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Jahlives".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-81721 json | openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing ... | Not Provided | 2026-08-27 | 2026-09-02 |
| CVE-2026-81720 json | openssl_encrypt before 1.4.9 fails to validate the memory_cost parameter from identity file protection blocks, allowing attac... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81719 json | openssl_encrypt before 1.4.9 executes untrusted third-party plugins with insufficient controls: the plugin signature policy d... | Not Provided | 2026-08-27 | 2026-09-02 |
| CVE-2026-81717 json | openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose t... | Not Provided | 2026-08-27 | 2026-09-02 |
| CVE-2026-81716 json | openssl_encrypt (pip: openssl-encrypt) versions before 1.4.9 contain a path traversal flaw in PluginSandbox._is_safe_path, wh... | Not Provided | 2026-08-27 | 2026-09-02 |
| CVE-2026-81715 json | openssl_encrypt (pip package openssl-encrypt) versions <= 1.4.8 do not redact the keyserver bearer token passed as the positi... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81714 json | openssl_encrypt (pip: openssl-encrypt) versions <= 1.4.8 use suffix-tolerant fingerprint matching in enroll_trust_key when bi... | Not Provided | 2026-08-27 | 2026-09-02 |
| CVE-2026-81706 json | openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allo... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81705 json | openssl-encrypt before 1.4.9 fails to redact the file password in its --debug argv dump when the password is supplied via bun... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81704 json | openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile hand... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81703 json | openssl_encrypt versions before 1.4.9 fail to validate encryption status of embedded post-quantum private keys in file metada... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81702 json | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowin... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81701 json | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-l... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81700 json | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accep... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81699 json | openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing atta... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81698 json | openssl_encrypt versions before 1.4.9 contain a shell injection vulnerability in the info command's reconstructed CLI block t... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81696 json | openssl_encrypt versions before 1.4.9 fail to sanitize terminal control characters in file metadata printed by the info comma... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81695 json | openssl_encrypt versions before 1.4.9 fail to escape attacker-controlled key_id values printed to stderr during decrypt auto-... | Not Provided | 2026-08-27 | 2026-09-01 |
| CVE-2026-81694 json | openssl-encrypt (pip package, versions <= 1.4.8) fails to sanitize filenames read from untrusted drive data (outside the AES-... | Not Provided | 2026-08-27 | 2026-09-03 |
| CVE-2026-81693 json | openssl_encrypt before 1.4.9 fails to validate the total field from QR JSON payloads before materializing ranges. Attackers c... | Not Provided | 2026-08-27 | 2026-09-02 |