Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Firmware MEDIUM 6.5
CVE-2016-6257

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ult…

Fix: after 024.003.00027
Fix from $1,600 2016-08-02
Crosswalk HIGH 8.1
CVE-2016-5672

Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of …

Fix: after 19.49.514.4
Fix from $1,950 2016-08-01
Packetshaper S Series HIGH 8.1
CVE-2016-5774

The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other inf…

Mitigation only
Fix from $1,950 2016-07-12
Hud Web HIGH 7.5
CVE-2016-2364

The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across differ…

Fix: after 1.4.1
Fix from $1,950 2016-06-20
Ios Receiver MEDIUM 6.1
CVE-2016-5433

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

Fix: after 6.1.5
Fix from $1,600 2016-06-17
Ubuntu Linux MEDIUM 5.9
CVE-2012-6702

Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat …

Fix: 2.2.0+
Fix from $1,600 2016-06-16
Hilink App MEDIUM 5.5
CVE-2016-4005

The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact v…

Fix: after 3.19.1
Fix from $1,600 2016-06-13
Pcm600 MEDIUM 6.5
CVE-2016-4524

ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sens…

Fix: after 2.6
Fix from $1,600 2016-06-10
Bac 5051e Firmware MEDIUM 5.3
CVE-2016-4495

KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration f…

Mitigation only
Fix from $1,600 2016-06-10
Debian Linux HIGH 7.5
CVE-2016-1902

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate ran…

Fix: after 2.3.36
Fix from $1,950 2016-06-01
Botan HIGH 7.5
CVE-2014-9742

The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remo…

Fix: after 1.10.7
Fix from $1,950 2016-05-13
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-2107EPSS 89%

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …

Fix: after 1.0.1s
Fix from $1,600 2016-05-05
Syslink Sl 1000 Modular Gateway Firmware HIGH 7.5
CVE-2016-2333

SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different cu…

Mitigation only
Fix from $1,950 2016-04-25
Ubuntu Linux HIGH 7.4
CVE-2016-2113

Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-midd…

Patch available
Fix from $1,950 2016-04-25
Integraxor HIGH 7.5
CVE-2016-2306

The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the networ…

Fix: after 4.2.4502
Fix from $1,950 2016-04-22
Ubuntu Linux MEDIUM 6.5
CVE-2013-7449

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a do…

Fix: after 2.10.1
Fix from $1,600 2016-04-21
Fedora HIGH 7.5
CVE-2016-3071

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

Mitigation only
Fix from $1,950 2016-04-18
Junos MEDIUM 5.9
CVE-2016-1273

Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient ent…

Fix: after 13.2x51
Fix from $1,600 2016-04-15
Fedora HIGH 7.5
CVE-2016-3125EPSS 7%

The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weak…

Fix: after 1.3.5
Fix from $1,950 2016-04-05
Iphone Os MEDIUM 5.9
CVE-2016-1788

Messages in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 does not properly implement a cryptographic protection mechanism, which…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Mac Os X Server HIGH 7.5
CVE-2016-1777

Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection …

Fix: after 5.0.15
Fix from $1,950 2016-03-24
Software Update MEDIUM 5.9
CVE-2016-1731

Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying t…

Fix: after 2.1.3.127
Fix from $1,600 2016-03-14
OpenSSL MEDIUM 5.9
CVE-2016-0800EPSS 82%

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…

Mitigation only
Fix from $1,600 2016-03-01
Ubuntu Linux CRITICAL 9.8
CVE-2015-8805

The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Ubuntu Linux CRITICAL 9.8
CVE-2015-8804

x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Ubuntu Linux CRITICAL 9.8
CVE-2015-8803

The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implement…

Fix: after 3.1.1
Fix from $2,300 2016-02-23
Security Access Manager 9.0 Firmware HIGH 7.5
CVE-2015-5012

The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 do…

Patch available
Fix from $1,950 2016-02-15
OpenSSL MEDIUM 5.9
CVE-2015-3197EPSS 11%

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…

Patch available
Fix from $1,600 2016-02-15
Secureworks MEDIUM 6.8
CVE-2016-2268

Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sens…

Patch available
Fix from $1,600 2016-02-08
Firefox MEDIUM 5.3
CVE-2016-1948

Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2016-01-31