Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Pipa C211 Web Interface HIGH 9.7
CVE-2014-2046

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obt…

No fix yet
Fix from $1,950 2014-05-14
Foreman MEDIUM 5.0
CVE-2013-0173

Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attac…

Fix: after 1.0
Fix from $1,600 2014-05-08
Rsa Access Manager MEDIUM 6.9
CVE-2014-0646

The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 befor…

Mitigation only
Fix from $1,600 2014-05-01
Integraxor MEDIUM 5.0
CVE-2014-0786

Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverag…

Fix: after 4.1.4390
Fix from $1,600 2014-05-01
Enterprise Mrg MEDIUM 5.0
CVE-2013-6445

Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier…

Mitigation only
Fix from $1,600 2014-04-30
Harmony MEDIUM 5.0
CVE-2013-7372

The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.…

Fix: after 6.0
Fix from $1,600 2014-04-29
Update Manager MEDIUM 6.4
CVE-2011-3152

DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x b…

Fix: after 1
Fix from $1,600 2014-04-27
Misli.com App MEDIUM 6.4
CVE-2014-2992

The Misli.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers …

Mitigation only
Fix from $1,600 2014-04-26
Birebin.com App MEDIUM 6.4
CVE-2014-2993

The Birebin.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server…

Mitigation only
Fix from $1,600 2014-04-26
Poco C\+\+ Libraries MEDIUM 6.4
CVE-2014-0350

The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof …

Fix: after 1.4.6
Fix from $1,600 2014-04-26
Cyassl MEDIUM 5.8
CVE-2014-2900

wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers …

Fix: after 2.9.0
Fix from $1,600 2014-04-22
Fedora MEDIUM 5.0
CVE-2013-6371

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data,…

Fix: 0.12-20140410+
Fix from $1,600 2014-04-22
Rbovirt MEDIUM 6.8
CVE-2014-0036

The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-m…

Fix: after 0.0.23
Fix from $1,600 2014-04-17
Curl MEDIUM 5.8
CVE-2014-0139

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'…

Mitigation only
Fix from $1,600 2014-04-15
Bsafe Micro Edition Suite MEDIUM 5.8
CVE-2014-0636

EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows m…

Mitigation only
Fix from $1,600 2014-04-11
Vsphere Client MEDIUM 5.8
CVE-2014-1210

VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attac…

Mitigation only
Fix from $1,600 2014-04-11
Cognos Express MEDIUM 5.0
CVE-2013-5444

The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encr…

Mitigation only
Fix from $1,600 2014-03-25
Cognos Express MEDIUM 5.0
CVE-2013-5445

IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext i…

Mitigation only
Fix from $1,600 2014-03-25
Simatic S7 Cpu 1200 Firmware HIGH 8.3
CVE-2014-2250

The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easi…

Fix: after 3.0.2
Fix from $1,950 2014-03-24
Jansson MEDIUM 5.0
CVE-2013-6401

Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to …

Fix: after 2.4
Fix from $1,600 2014-03-21
Demaecan MEDIUM 5.8
CVE-2014-1976

The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers …

Fix: after 2.1.0
Fix from $1,600 2014-03-18
Puppet Enterprise HIGH 8.5
CVE-2013-1398

The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows rem…

Fix: after 2.7.0
Fix from $1,950 2014-03-14
Powerarchiver MEDIUM 5.0
CVE-2014-2319

The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which ma…

Fix: after 14.02.03
Fix from $1,600 2014-03-14
Linux Kernel MEDIUM 5.2
CVE-2014-0102

The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings…

Fix: after 3.13.6
Fix from $1,600 2014-03-11
Gnutls MEDIUM 5.8
CVE-2014-0092EPSS 30%

lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from …

Fix: after 3.2.11
Fix from $1,600 2014-03-07
Algo One MEDIUM 5.0
CVE-2013-5468

IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,…

Mitigation only
Fix from $1,600 2014-03-05
Denny\'s MEDIUM 5.8
CVE-2014-1967

The Denny's application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spo…

Fix: after 2.0.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 6.2
CVE-2014-0741

The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified…

Fix: after 10.0
Fix from $1,600 2014-02-27
Studio Extension For System Z HIGH 10.0
CVE-2013-3712

SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector…

No fix yet
Fix from $1,950 2014-02-26
Chrome MEDIUM 6.4
CVE-2013-6659

The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not preve…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24