Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Curl MEDIUM 5.9
CVE-2021-22947

When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respo…

Fix: 7.79.0+
Fix from $1,600 2021-09-29
Aws Encryption Sdk HIGH 8.1
CVE-2020-8897

A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committi…

Fix: 2.0.0+
Fix from $1,950 2020-11-16
Bsafe Crypto C Micro Edition HIGH 7.5
CVE-2019-3731

RSA BSAFE Crypto-C Micro Edition versions prior to 4.1.4 and RSA Micro Edition Suite versions prior to 4.4 are vulnerable to an Information Exposure …

Fix: 4.0.13 / 4.1.4+
Fix from $1,950 2019-09-30
Bsafe Cert J MEDIUM 6.5
CVE-2019-3739

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generat…

Fix: 6.2.5 / 19.1.0.0.0.210420+
Fix from $1,600 2019-09-18
Bsafe Cert J MEDIUM 6.5
CVE-2019-3740

RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key genera…

Fix: 6.2.5 / 12.2.0.1.22+
Fix from $1,600 2019-09-18
Secvest Wireless Alarm System Fuaa50000 Firmware HIGH 7.5
CVE-2019-14261

An issue was discovered on ABUS Secvest FUAA50000 3.01.01 devices. Due to an insufficient implementation of jamming detection, an attacker is able to…

No fix yet
Fix from $1,950 2019-09-03
Cospas Sarsat System CRITICAL 9.1
CVE-2018-14062

The COSPAS-SARSAT protocol allows remote attackers to forge messages, replay encrypted messages, conduct denial of service attacks, and send private …

Mitigation only
Fix from $2,300 2019-08-15
Ubuntu Linux HIGH 8.1
CVE-2019-9506

The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker fr…

Mitigation only
Fix from $1,950 2019-08-14
Industrial Network Director MEDIUM 5.9
CVE-2019-1940

A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote…

Fix: 1.7+
Fix from $1,600 2019-07-17
Mdm9150 Firmware HIGH 7.8
CVE-2018-5913

A non-time constant function memcmp is used which creates a side channel that could leak information in Snapdragon Auto, Snapdragon Compute, Snapdrag…

Mitigation only
Fix from $1,950 2019-06-14
Simatic Mv420 Firmware MEDIUM 5.3
CVE-2019-10926

A vulnerability has been identified in SIMATIC MV400 family (All Versions < V7.0.6). Communication with the device is not encrypted. Data transmitted…

Mitigation only
Fix from $1,600 2019-06-12
Siteomat HIGH 8.6
CVE-2017-14852

An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificat…

Fix: 6.4.414.084+
Fix from $1,950 2019-06-03
Simatic Hmi Comfort Panels Firmware MEDIUM 6.5
CVE-2019-6576

A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor Panels 7" & 1…

Fix: 15.1+
Fix from $1,600 2019-05-14
Secvest Wireless Alarm System Fuaa50000 Firmware HIGH 8.1
CVE-2019-9861

Due to the use of an insecure RFID technology (MIFARE Classic), ABUS proximity chip keys (RFID tokens) of the ABUS Secvest FUAA50000 wireless alarm s…

No fix yet
Fix from $1,950 2019-05-14
Nexus 9332pq Firmware CRITICAL 9.8
CVE-2019-1804

A vulnerability in the SSH key management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow a…

Mitigation only
Fix from $2,300 2019-05-03
Enterprise Transport Security MEDIUM 5.9
CVE-2019-9191

The ETSI Enterprise Transport Security (ETS, formerly known as eTLS) protocol does not provide per-session forward secrecy.

Mitigation only
Fix from $1,600 2019-02-26
Iiot Monitor MEDIUM 5.5
CVE-2018-7839

A Cryptographic Issue (CWE-310) vulnerability exists in IIoT Monitor 3.1.38 which could allow information disclosure.

No fix yet
Fix from $1,600 2019-02-06
Mdm9635m Firmware CRITICAL 9.8
CVE-2017-18160

AGPS session failure in GNSS module due to cyphersuites are hardcoded and needed manual update everytime in snapdragon mobile and snapdragon wear in …

Mitigation only
Fix from $2,300 2019-01-18
Wolfssl MEDIUM 5.9
CVE-2018-16870

It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This ma…

Fix: 3.15.7+
Fix from $1,600 2019-01-03
Mdm9607 Firmware MEDIUM 5.5
CVE-2017-18327

Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in version…

Mitigation only
Fix from $1,600 2019-01-03
Security Guardium HIGH 7.5
CVE-2017-1268

IBM Security Guardium 10 and 10.5 uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the softw…

Fix: after 10.5
Fix from $1,950 2018-12-13
Consul MEDIUM 5.9
CVE-2018-19653

HashiCorp Consul 0.5.1 through 1.4.0 can use cleartext agent-to-agent RPC communication because the verify_outgoing setting is improperly documented.…

Fix: after 1.4.0
Fix from $1,600 2018-12-09
Rp 210e Firmware HIGH 8.8
CVE-2018-5402

The Auto-Maskin DCU 210E, RP-210E, and Marine Pro Observer Android App use an embedded webserver that uses unencrypted plaintext for the transmission…

Mitigation only
Fix from $1,950 2018-10-08
Chrome MEDIUM 5.3
CVE-2017-15423

Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA51…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Usg2205bsr Firmware MEDIUM 5.9
CVE-2017-17305

Some Huawei Firewall products USG2205BSR V300R001C10SPC600; USG2220BSR V300R001C00; USG5120BSR V300R001C00; USG5150BSR V300R001C00 have a Bleichenbac…

Mitigation only
Fix from $1,600 2018-08-21
Wap121 Firmware MEDIUM 5.3
CVE-2018-0412

A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireles…

Fix: after 1.0.6.6
Fix from $1,600 2018-08-15
Rse6500 Firmware MEDIUM 5.9
CVE-2017-17174

Some Huawei products RSE6500 V500R002C00; SoftCo V200R003C20SPCb00; VP9660 V600R006C10; eSpace U1981 V100R001C20; V200R003C20; V200R003C30; V200R003C…

Mitigation only
Fix from $1,600 2018-07-31
Debian Linux HIGH 7.4
CVE-2017-12151

A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The con…

Fix: 4.4.16 / 4.5.14+
Fix from $1,950 2018-07-27
Ubuntu Linux MEDIUM 6.8
CVE-2017-7526

libgcrypt before version 1.7.8 is vulnerable to a cache side-channel attack resulting into a complete break of RSA-1024 while using the left-to-right…

Fix: 1.7.8+
Fix from $1,600 2018-07-26
U Boot MEDIUM 6.4
CVE-2017-3226

Das U-Boot is a device bootloader that can read its configuration from an AES encrypted file. Devices that make use of Das U-Boot's AES-CBC encryptio…

Fix: 2017.09+
Fix from $1,600 2018-07-24