Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Unified Computing System MEDIUM 5.8
CVE-2012-4115

The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2013-10-21
Unified Computing System MEDIUM 5.8
CVE-2012-4114

The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man-in-the-middle attackers to w…

Mitigation only
Fix from $1,600 2013-10-19
Adaptive Security Appliance Software HIGH 7.1
CVE-2013-5507

The IPsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(1.7), when an IPsec VPN tunnel is enabled, allows remote …

Mitigation only
Fix from $1,950 2013-10-13
Airlive Od 2025hd HIGH 7.8
CVE-2013-3687

AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive in…

Mitigation only
Fix from $1,950 2013-10-11
Gnupg MEDIUM 5.8
CVE-2013-4351

GnuPG 1.4.x, 2.0.x, and 2.1.x treats a key flags subpacket with all bits cleared (no usage permitted) as if it has all bits set (all usage permitted)…

Mitigation only
Fix from $1,600 2013-10-10
Management Suite HIGH 7.8
CVE-2013-3593

Baramundi Management Suite 7.5 through 8.9 uses cleartext for (1) client-server communication and (2) data storage, which allows remote attackers to …

Mitigation only
Fix from $1,950 2013-10-03
Management Suite HIGH 7.8
CVE-2013-3624

The OS deployment feature in Baramundi Management Suite 7.5 through 8.9 stores credentials in cleartext on deployed machines, which allows remote att…

Mitigation only
Fix from $1,950 2013-10-03
Enterprise Security Api MEDIUM 5.8
CVE-2013-5960

The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.…

Fix: 2.1.0.1+
Fix from $1,600 2013-09-30
Linux Kernel MEDIUM 5.0
CVE-2013-4350

The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an int…

Patch available
Fix from $1,600 2013-09-25
Unified Computing System MEDIUM 5.8
CVE-2012-4073

The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-…

Mitigation only
Fix from $1,600 2013-09-20
Kde Workspace MEDIUM 5.0
CVE-2013-4132

KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote atta…

Fix: after 4.10.5
Fix from $1,600 2013-09-16
Socialminer MEDIUM 5.0
CVE-2013-5492

administration.jsp in Cisco SocialMiner allows remote attackers to obtain sensitive information by sniffing the network for HTTP client-server traffi…

Mitigation only
Fix from $1,600 2013-09-13
Radiolinx Controlscape HIGH 9.3
CVE-2013-2803

ProSoft RadioLinx ControlScape before 6.00.040 uses a deficient PRNG algorithm and seeding strategy for passphrases, which makes it easier for remote…

Fix: after 6.00
Fix from $1,950 2013-09-09
Rational Policy Tester MEDIUM 6.8
CVE-2013-4062

IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof …

Mitigation only
Fix from $1,600 2013-09-09
Security Appscan MEDIUM 5.0
CVE-2013-0531

The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier…

Fix: after 8.7.0.0
Fix from $1,600 2013-09-08
Open Xchange Server MEDIUM 5.8
CVE-2013-1651

OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL server…

No fix yet
Fix from $1,600 2013-09-05
Globalprotect MEDIUM 5.8
CVE-2012-6606

Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle at…

Fix: after 1.1.6
Fix from $1,600 2013-08-31
Tburjr900 HIGH 9.3
CVE-2013-2782

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different cust…

Mitigation only
Fix from $1,950 2013-08-28
Yafuoku\! MEDIUM 5.8
CVE-2013-4699

The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-…

Fix: after 4.3.0
Fix from $1,600 2013-08-21
Japan Shopping MEDIUM 5.8
CVE-2013-4700

The Yahoo! Japan Shopping application 1.4 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle…

Fix: after 1.4
Fix from $1,600 2013-08-21
Cxf MEDIUM 6.4
CVE-2012-5575EPSS 6%

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe…

Mitigation only
Fix from $1,600 2013-08-19
Ruby MEDIUM 6.8
CVE-2013-4073

The OpenSSL::SSL.verify_certificate_identity function in lib/openssl/ssl.rb in Ruby 1.8 before 1.8.7-p374, 1.9 before 1.9.3-p448, and 2.0 before 2.0.…

Mitigation only
Fix from $1,600 2013-08-18
Oncell Gateway Firmware HIGH 7.1
CVE-2012-3039

Moxa OnCell Gateway G3111, G3151, G3211, and G3251 devices with firmware before 1.4 do not use a sufficient source of entropy for SSH and SSL keys, w…

Fix: after 1.3
Fix from $1,950 2013-08-09
Request Tracker MEDIUM 6.4
CVE-2012-6579

Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryption or sig…

Patch available
Fix from $1,600 2013-07-24
Nano 10 Plc Firmware HIGH 7.8
CVE-2013-2784

Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modb…

Mitigation only
Fix from $1,950 2013-07-10
Android HIGH 9.3
CVE-2013-4787EPSS 59%

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitra…

Mitigation only
Fix from $1,950 2013-07-09
Sterling B2b Integrator MEDIUM 5.0
CVE-2012-5936

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 do not set the secure flag for the session cookie in an https session, …

Mitigation only
Fix from $1,600 2013-07-03
Dasdec Eas HIGH 10.0
CVE-2013-0137EPSS 13%

The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2…

Fix: after 2.0-1
Fix from $1,950 2013-06-30
Firefox MEDIUM 5.0
CVE-2013-1699

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level…

Fix: after 21.0
Fix from $1,600 2013-06-26
Forticlient MEDIUM 5.4
CVE-2013-4669

FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; Forti…

Fix: after 4.3.3.445
Fix from $1,600 2013-06-25