Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Tapjoy Library MEDIUM 5.4
CVE-2014-5527

The Tapjoy library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt…

Mitigation only
Fix from $1,600 2014-09-09
Appsflyer MEDIUM 5.4
CVE-2014-5528

The Appsflyer library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and …

Mitigation only
Fix from $1,600 2014-09-09
Gameloft Library MEDIUM 5.4
CVE-2014-5529

The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o…

Mitigation only
Fix from $1,600 2014-09-09
Trafficdot MEDIUM 5.4
CVE-2014-2379

Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to …

Fix: after 2.10.2
Fix from $1,600 2014-09-05
Kindle MEDIUM 5.8
CVE-2014-3908

The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…

Fix: after 4.4.4
Fix from $1,600 2014-08-30
Pgp Desktop MEDIUM 5.0
CVE-2014-3436

Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,600 2014-08-22
Ameba MEDIUM 5.8
CVE-2014-3902

The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mi…

Fix: after 4.4.0
Fix from $1,600 2014-08-15
Webex Meetings Server MEDIUM 5.8
CVE-2014-3302

user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allow…

Fix: after 1.5
Fix from $1,600 2014-08-01
Debian Linux MEDIUM 5.0
CVE-2014-4911

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of servi…

Fix: after 1.2.10
Fix from $1,600 2014-07-22
Syncope MEDIUM 5.0
CVE-2014-3503EPSS 6%

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…

No fix yet
Fix from $1,600 2014-07-11
Integrated Management Module Firmware MEDIUM 5.0
CVE-2014-0860

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), an…

Fix: after 3.65
Fix from $1,600 2014-07-07
Jr East Japan MEDIUM 5.8
CVE-2014-2001

The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows m…

Fix: after 1.0
Fix from $1,600 2014-06-19
Powerpc Utils MEDIUM 5.0
CVE-2014-4040

snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning abo…

Mitigation only
Fix from $1,600 2014-06-17
Bsafe Share MEDIUM 5.0
CVE-2014-4191

The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algor…

Mitigation only
Fix from $1,600 2014-06-17
Bsafe Share MEDIUM 5.0
CVE-2014-4192

The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only…

Mitigation only
Fix from $1,600 2014-06-17
Bsafe Share MEDIUM 5.0
CVE-2014-4193

The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algo…

Mitigation only
Fix from $1,600 2014-06-17
Rsa Bsafe Toolkits MEDIUM 5.8
CVE-2013-6078

The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random …

Mitigation only
Fix from $1,600 2014-06-17
Ive Os MEDIUM 5.0
CVE-2014-3812

The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service …

Mitigation only
Fix from $1,600 2014-06-13
Phpcas MEDIUM 5.8
CVE-2012-5583

phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X…

Fix: after 1.3.1
Fix from $1,600 2014-06-06
Owncloud MEDIUM 5.0
CVE-2013-1941

The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation o…

Fix: after 4.0.13
Fix from $1,600 2014-06-04
Opensmtpd MEDIUM 5.0
CVE-2013-2125

OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by kee…

Fix: after 5.3.1
Fix from $1,600 2014-05-27
X3270 MEDIUM 5.8
CVE-2012-5662

x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

Fix: after 3.3.12
Fix from $1,600 2014-05-27
Java Sdk MEDIUM 5.8
CVE-2014-0878

The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh…

Mitigation only
Fix from $1,600 2014-05-26
Cloudstack MEDIUM 5.0
CVE-2013-2758EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se…

Patch available
Fix from $1,600 2014-05-23
Python Oauth2 MEDIUM 5.8
CVE-2013-4347

The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, w…

Patch available
Fix from $1,600 2014-05-20
Livezilla MEDIUM 6.8
CVE-2013-7385

LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php,…

Fix: after 5.1.2.1
Fix from $1,600 2014-05-19
Exceed Ondemand MEDIUM 5.0
CVE-2013-6805

OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffi…

Mitigation only
Fix from $1,600 2014-05-19
Exceed Ondemand MEDIUM 6.8
CVE-2013-6807

The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certi…

Mitigation only
Fix from $1,600 2014-05-19
Exceed Ondemand MEDIUM 6.4
CVE-2013-6994

OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing…

Mitigation only
Fix from $1,600 2014-05-19
Bilyoner MEDIUM 5.8
CVE-2014-3750

The Bilyoner application before 2.3.1 for Android and before 4.6.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t…

Fix: after 4.6
Fix from $1,600 2014-05-16