Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Wemo Home Automation Firmware HIGH 7.8
CVE-2013-6950

The Belkin WeMo Home Automation firmware before 3949 does not use SSL for the distribution feed, which allows man-in-the-middle attackers to install …

Mitigation only
Fix from $1,950 2014-02-22
Wemo Home Automation Firmware HIGH 7.1
CVE-2013-6951

The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle a…

Mitigation only
Fix from $1,950 2014-02-22
Wemo Home Automation Firmware HIGH 10.0
CVE-2013-6952

The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware updates an…

Mitigation only
Fix from $1,950 2014-02-22
Sharefile Mobile MEDIUM 5.8
CVE-2014-1910

Citrix ShareFile Mobile and ShareFile Mobile for Tablets before 2.4.4 for Android do not verify X.509 certificates from SSL servers, which allow man-…

Fix: after 2.4
Fix from $1,600 2014-02-21
Swift MEDIUM 5.8
CVE-2013-6396

The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allow…

Mitigation only
Fix from $1,600 2014-02-18
Bsafe Ssl J MEDIUM 5.0
CVE-2014-0626

The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote attackers to bypass intended c…

Mitigation only
Fix from $1,600 2014-02-18
Bsafe Ssl J MEDIUM 5.0
CVE-2014-0627

The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a w…

Mitigation only
Fix from $1,600 2014-02-18
Kexec Tools MEDIUM 5.7
CVE-2011-3588

The SSH configuration in the Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3589

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Kexec Tools MEDIUM 5.7
CVE-2011-3590

The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat E…

Fix: after 2.0.0-188
Fix from $1,600 2014-02-15
Standards Based Linux Common Information Model Client MEDIUM 5.0
CVE-2012-2328

internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sb…

Fix: after 2.1.11
Fix from $1,600 2014-02-10
Simatic Wincc Open Architecture MEDIUM 5.0
CVE-2014-1696

Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain acce…

Fix: after 3.12
Fix from $1,600 2014-02-07
Ivr Pro HIGH 10.0
CVE-2013-6838

An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ…

Mitigation only
Fix from $1,950 2014-01-28
Itunes MEDIUM 5.8
CVE-2014-1242

Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control ov…

Fix: after 11.1.3
Fix from $1,600 2014-01-23
Telepathy Gabble MEDIUM 5.0
CVE-2013-1769

A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (N…

Patch available
Fix from $1,600 2014-01-21
Network Security Services MEDIUM 5.8
CVE-2013-1740

The ssl_Do1stHandshake function in sslsecur.c in libssl in Mozilla Network Security Services (NSS) before 3.15.4, when the TLS False Start feature is…

Fix: after 3.15.3
Fix from $1,600 2014-01-18
Chrome MEDIUM 5.0
CVE-2012-2898

Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibox URL via vectors involving SSL error messages, a…

Fix: after 21.0.1180.81
Fix from $1,600 2014-01-05
Fat Free Crm MEDIUM 5.0
CVE-2013-7222

config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easie…

Fix: after 0.12.0
Fix from $1,600 2014-01-02
Onedc MEDIUM 5.8
CVE-2013-6812

The ONEDC app before 1.7 for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof serv…

Fix: after 1.51
Fix from $1,600 2013-12-28
Fedora MEDIUM 5.1
CVE-2013-4550

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr b…

Fix: after 0.8.8
Fix from $1,600 2013-12-24
TYPO3 MEDIUM 6.5
CVE-2013-7075

The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remot…

Mitigation only
Fix from $1,600 2013-12-23
Ireland Cisco Epc2425 HIGH 9.3
CVE-2013-7136EPSS 7%

The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it eas…

No fix yet
Fix from $1,950 2013-12-19
Content Manager Ondemand For Multiplatforms HIGH 7.8
CVE-2013-6329

IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of…

Patch available
Fix from $1,950 2013-12-17
Unified Communications Manager HIGH 7.3
CVE-2013-7030EPSS 5%

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phon…

No fix yet
Fix from $1,950 2013-12-12
Fedora MEDIUM 5.9
CVE-2013-6673

Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of tr…

Fix: 2.23 / 24.2+
Fix from $1,600 2013-12-11
Drupal MEDIUM 6.8
CVE-2013-6386

Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote a…

Patch available
Fix from $1,600 2013-12-07
Advanced Management Module Firmware MEDIUM 6.4
CVE-2013-6718

The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account na…

Mitigation only
Fix from $1,600 2013-12-01
Ubuntu Linux MEDIUM 5.8
CVE-2013-1058

maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via…

Fix: after 12.04.4
Fix from $1,600 2013-11-23
Kdrive MEDIUM 5.8
CVE-2013-5999

Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers …

Fix: after 1.21.0.1878
Fix from $1,600 2013-11-22
Mac Os X MEDIUM 5.0
CVE-2013-5182

Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the mul…

Fix: after 10.8.5
Fix from $1,600 2013-10-24