Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Unclassified HIGH 7.8
CVE-2017-13091

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13092

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13093

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13094

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13095

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13096

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Unclassified HIGH 7.8
CVE-2017-13097

The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig…

Mitigation only
Fix from $1,950 2018-07-13
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-3017

IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat crypt…

Fix: 7.2.1.5+
Fix from $1,950 2018-07-09
Bitcoin Core HIGH 7.5
CVE-2016-10725

In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because…

Fix: 0.13.0+
Fix from $1,950 2018-07-05
Suse Linux Enterprise Desktop MEDIUM 5.3
CVE-2011-4190

The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi…

Mitigation only
Fix from $1,600 2018-06-08
Bc Java HIGH 7.4
CVE-2016-1000344

In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and …

Fix: after 1.55
Fix from $1,950 2018-06-04
Bc Java HIGH 7.4
CVE-2016-1000352

In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and …

Fix: after 1.55
Fix from $1,950 2018-06-04
Npm Test Sqlite3 Trunk HIGH 8.1
CVE-2016-10695

The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, …

Fix: after 4.0.1
Fix from $1,950 2018-06-04
Windows Latestchromedriver HIGH 8.1
CVE-2016-10696

windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTP, which l…

Mitigation only
Fix from $1,950 2018-06-04
React Native Baidu Voice Synthesizer HIGH 8.1
CVE-2016-10697

react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources o…

Mitigation only
Fix from $1,950 2018-06-04
Rs Brightcove HIGH 8.1
CVE-2016-10676

rs-brightcove is a wrapper around brightcove's web api rs-brightcove downloads source file resources over HTTP, which leaves it vulnerable to MITM at…

Fix: after 0.0.2
Fix from $1,950 2018-06-04
Google Closure Tools Latest HIGH 8.1
CVE-2016-10677

google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-latest do…

Fix: after 0.1.1
Fix from $1,950 2018-06-04
Serc.js HIGH 8.1
CVE-2016-10678

serc.js is a Selenium RC process wrapper serc.js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible…

Mitigation only
Fix from $1,950 2018-06-04
Arcanist HIGH 8.1
CVE-2016-10683

arcanist downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swappi…

Mitigation only
Fix from $1,950 2018-06-04
Healthcenter HIGH 8.1
CVE-2016-10684

healthcenter - IBM Monitoring and Diagnostic Tools health Center agent healthcenter downloads binary resources over HTTP, which leaves it vulnerable …

Mitigation only
Fix from $1,950 2018-06-04
Pk App Wonderbox HIGH 8.1
CVE-2016-10685

pk-app-wonderbox is an integration with wonderbox pk-app-wonderbox downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. …

Mitigation only
Fix from $1,950 2018-06-04
Fis Sass All HIGH 8.1
CVE-2016-10686

fis-sass-all is another libsass wrapper for node. fis-sass-all downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m…

Mitigation only
Fix from $1,950 2018-06-04
Windows Selenium Chromedriver HIGH 8.1
CVE-2016-10687

windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, w…

Mitigation only
Fix from $1,950 2018-06-04
Haxe HIGH 8.1
CVE-2016-10688

Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulnerable t…

Fix: after 3.4.7
Fix from $1,950 2018-06-04
Windows Iedriver HIGH 8.1
CVE-2016-10689

The windows-iedriver module downloads fixed version of iedriverserver.exe windows-iedriver downloads binary resources over HTTP, which leaves it vuln…

Mitigation only
Fix from $1,950 2018-06-04
Openframe Ascii Image HIGH 8.1
CVE-2016-10690

openframe-ascii-image module is an openframe plugin which adds support for ascii images via fim. openframe-ascii-image downloads resources over HTTP,…

Mitigation only
Fix from $1,950 2018-06-04
Windows Seleniumjar HIGH 8.1
CVE-2016-10691

windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves it vulner…

Mitigation only
Fix from $1,950 2018-06-04
Haxeshim HIGH 8.1
CVE-2016-10692

haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be po…

Fix: after 0.12.4
Fix from $1,950 2018-06-04
Pm2 Kafka HIGH 8.1
CVE-2016-10693

pm2-kafka is a PM2 module that installs and runs a kafka server pm2-kafka downloads binary resources over HTTP, which leaves it vulnerable to MITM at…

Mitigation only
Fix from $1,950 2018-06-04
Alto Saxophone HIGH 8.1
CVE-2016-10694

alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resourc…

Fix: 2.25.1+
Fix from $1,950 2018-06-04