Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Firefox MEDIUM 6.5
CVE-2016-1938

The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, imprope…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Weos CRITICAL 9.0
CVE-2015-7923

Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle atta…

Mitigation only
Fix from $2,300 2016-01-30
Chrome MEDIUM 6.5
CVE-2016-1618

Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi…

Fix: after 47.0.2526.106
Fix from $1,600 2016-01-25
Web Viewer HIGH 7.5
CVE-2015-8281

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Fritz\! Os HIGH 8.1
CVE-2014-8886EPSS 6%

AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to c…

Fix: after 6.23
Fix from $1,950 2016-01-08
1000 Ccu Gms HIGH 7.5
CVE-2014-3260

Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging improper use of cryptography.

Mitigation only
Fix from $1,950 2015-12-31
Screenos MEDIUM 5.0
CVE-2015-7756

The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.…

Mitigation only
Fix from $1,600 2015-12-19
Gprs Cs2300 R Firmware MEDIUM 6.4
CVE-2015-7286

CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hardcoded keys, which makes it ea…

No fix yet
Fix from $1,600 2015-11-25
Manufacturing Integration And Intelligence MEDIUM 5.0
CVE-2015-8329

SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct down…

No fix yet
Fix from $1,600 2015-11-24
Windows 7 MEDIUM 5.8
CVE-2015-6112

SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2015-11-11
Party Track Sdk MEDIUM 5.8
CVE-2015-5655

The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo…

Fix: after 1.6.5
Fix from $1,600 2015-11-10
Leap MEDIUM 5.0
CVE-2015-7940

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obt…

Fix: after 1.50
Fix from $1,600 2015-11-09
Arcsight Smartconnectors MEDIUM 6.8
CVE-2015-2902

HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devi…

Fix: after 7.1.5
Fix from $1,600 2015-11-04
Iq Panel HIGH 9.3
CVE-2015-6033

Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass…

Fix: after 1.5.0
Fix from $1,950 2015-10-31
Librsync MEDIUM 5.8
CVE-2014-8242

librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birt…

Fix: 1.0.0+
Fix from $1,600 2015-10-26
Change And Configuration Management Database MEDIUM 5.0
CVE-2015-1934

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x befor…

Patch available
Fix from $1,600 2015-10-04
Vcenter Server MEDIUM 5.8
CVE-2015-6932

VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attack…

Mitigation only
Fix from $1,600 2015-09-18
Compas MEDIUM 5.8
CVE-2015-5717

The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi…

Fix: after 1.5
Fix from $1,600 2015-08-31
Foreman MEDIUM 5.0
CVE-2015-1816

Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a craft…

Fix: after 1.7.3
Fix from $1,600 2015-08-14
Fortios MEDIUM 6.4
CVE-2015-2323

FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to Fort…

Mitigation only
Fix from $1,600 2015-08-11
Rational Test Virtualization Server MEDIUM 5.0
CVE-2015-1913

Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.…

Patch available
Fix from $1,600 2015-06-30
Epolicy Orchestrator MEDIUM 5.8
CVE-2015-2859

Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X…

Patch available
Fix from $1,600 2015-06-23
702w Industrial Wireless Access Point HIGH 8.8
CVE-2012-4716

N-Tron 702-W Industrial Wireless Access Point devices use the same (1) SSH and (2) HTTPS private keys across different customers' installations, whic…

Mitigation only
Fix from $1,950 2015-06-13
Smartsocket MEDIUM 6.8
CVE-2015-4080

The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sens…

No fix yet
Fix from $1,600 2015-06-09
Pacemaker Configuration System MEDIUM 6.8
CVE-2015-1848

The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote atta…

Fix: after 0.9.137
Fix from $1,600 2015-05-14
.net Framework MEDIUM 5.0
CVE-2015-1672EPSS 18%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performanc…

Mitigation only
Fix from $1,600 2015-05-13
System Update HIGH 8.3
CVE-2015-2233

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which a…

Fix: after 5.06.0027
Fix from $1,950 2015-05-12
Homecontrol For Room Automation MEDIUM 5.4
CVE-2015-3610

The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows ma…

Fix: after 2.0.0
Fix from $1,600 2015-05-07
Thinkserver Rd650 Firmware MEDIUM 5.0
CVE-2015-3322

Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passw…

Fix: after 1.25.0
Fix from $1,600 2015-04-16
Rational Clearcase HIGH 9.4
CVE-2014-6221

The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0…

Patch available
Fix from $1,950 2015-04-06