{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-22T00:54:18.644","vulnerabilities":[{"cve":{"id":"CVE-2019-10764","sourceIdentifier":"report@snyk.io","published":"2019-11-18T22:15:11.157","lastModified":"2026-06-17T02:11:37.687","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In elliptic-php versions priot to 1.0.6, Timing attacks might be possible which can result in practical recovery of the long-term private key generated by the library under certain conditions. Leakage of a bit-length of the scalar during scalar multiplication is possible on an elliptic curve which might allow practical recovery of the long-term private key."},{"lang":"es","value":"En elliptic-php versiones anteriores a 1.0.6, ataques de sincronización pueden ser posibles, lo que resulta en la recuperación práctica de la clave privada a largo plazo generada por la biblioteca bajo determinadas condiciones. La fuga de una longitud de bits del escalar durante la multiplicación escalar es posible sobre una curva de elliptic que podría permitir la recuperación práctica de la clave privada a largo plazo."}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"simplito/elliptic-php","versions":[{"version":"All versions prior to version 2.5","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","baseScore":7.4,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":5.2}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-203"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:simplito:elliptic-php:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.6","matchCriteriaId":"3BAD364B-8CA6-481A-8BD3-04D6C9FB4911"}]}]}],"references":[{"url":"https://minerva.crocs.fi.muni.cz/","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-PHP-SIMPLITOELLIPTICPHP-534576","source":"report@snyk.io","tags":["Third Party Advisory"]},{"url":"https://minerva.crocs.fi.muni.cz/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-PHP-SIMPLITOELLIPTICPHP-534576","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}}]}