Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Mednet MEDIUM 5.0
CVE-2014-5403

Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to…

Fix: after 5.8
Fix from $1,600 2015-04-03
Gnutls MEDIUM 5.0
CVE-2015-0282

GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote …

Fix: after 3.0.9
Fix from $1,600 2015-03-24
Mod Gnutls MEDIUM 5.0
CVE-2015-2091

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is …

Fix: after 0.5.1
Fix from $1,600 2015-03-13
Openstack HIGH 7.5
CVE-2014-3691

Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot…

Fix: after 1.5.3
Fix from $1,950 2015-03-09
Spcanywhere MEDIUM 5.8
CVE-2015-1596

The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle …

Fix: after 1.4.1
Fix from $1,600 2015-03-07
Redirector Sdk MEDIUM 5.0
CVE-2015-2078

The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qu…

No fix yet
Fix from $1,600 2015-02-24
Wincc MEDIUM 5.0
CVE-2015-1358

The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) bef…

Mitigation only
Fix from $1,600 2015-02-18
Proxyclient HIGH 7.1
CVE-2015-1454

Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates,…

Fix: 3.3.3.3 / 3.4.4.10+
Fix from $1,950 2015-02-02
Forticlient MEDIUM 5.0
CVE-2015-1453

The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers t…

Fix: after 5.2.3.091
Fix from $1,600 2015-02-02
Security Appscan MEDIUM 5.8
CVE-2014-8918

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2015-02-02
Security Appscan MEDIUM 5.0
CVE-2014-6136

IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive informa…

Mitigation only
Fix from $1,600 2015-02-02
Iphone Os MEDIUM 6.8
CVE-2014-8840

The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio…

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Kde Applications MEDIUM 5.0
CVE-2013-7252

kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes i…

Fix: after 14.11.3
Fix from $1,600 2015-01-18
Multilink Ml3100 Firmware MEDIUM 5.0
CVE-2014-5419

GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar…

Fix: after 5.2.0
Fix from $1,600 2015-01-17
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-5386

The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the rand…

Fix: after 3.2.0
Fix from $1,600 2014-12-28
Pwgen MEDIUM 5.0
CVE-2013-4442

Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dep…

Fix: after 2.06
Fix from $1,600 2014-12-19
Security Access Manager For Web MEDIUM 5.0
CVE-2014-6087

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…

Mitigation only
Fix from $1,600 2014-12-18
Security Access Manager For Mobile MEDIUM 5.0
CVE-2014-6084

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier…

Mitigation only
Fix from $1,600 2014-12-18
Tivoli Endpoint Manager Mobile Device Management HIGH 9.3
CVE-2014-6140EPSS 6%

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations…

Fix: after 9.0
Fix from $1,950 2014-12-06
WordPress MEDIUM 6.8
CVE-2014-9037

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle…

Fix: after 3.7.4
Fix from $1,600 2014-11-25
Polarssl MEDIUM 5.0
CVE-2014-8627

PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified…

Mitigation only
Fix from $1,600 2014-11-24
Curl MEDIUM 5.0
CVE-2014-3620

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a …

Fix: after 10.10.4
Fix from $1,600 2014-11-18
Curl MEDIUM 5.0
CVE-2014-3613EPSS 7%

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send…

Fix: after 10.10.4
Fix from $1,600 2014-11-18
Helion Cloud Development Platform HIGH 10.0
CVE-2014-7878EPSS 10%

The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses…

Mitigation only
Fix from $1,950 2014-11-14
Enterprise Linux Desktop MEDIUM 5.0
CVE-2014-8564

The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att…

Patch available
Fix from $1,600 2014-11-13
Commoncryptolib HIGH 7.5
CVE-2014-8587

SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attacke…

Fix: after 8.4.29
Fix from $1,950 2014-11-04
Joomla\! HIGH 7.5
CVE-2014-7228EPSS 55%

Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi…

No fix yet
Fix from $1,950 2014-11-03
Plone MEDIUM 5.0
CVE-2012-6661

Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it e…

Fix: after 4.2.2
Fix from $1,600 2014-11-03
Xenmobile MEDIUM 5.0
CVE-2014-8495

Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows cont…

Fix: after 9.0.3
Fix from $1,600 2014-10-31
Hijab Modern MEDIUM 5.4
CVE-2014-8538

The Hijab Modern (aka com.Aisyaidea.HijabModern) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in…

Mitigation only
Fix from $1,600 2014-10-29