I know that factoring (which attacks RSA) is sub-exponential, and I know that implementations of RSA (bad choices of primes, timing attacks, etc) can have weaknesses ... I'm just interested as to whether you have something else in mind.
Thx.
Reference to a scientific paper is given: https://www.ams.org/notices/199612/pomerance.pdf