Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Acu MEDIUM 6.5
CVE-2012-4960

The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300,…

Mitigation only
Fix from $1,600 2013-06-20
Ar 18 1x HIGH 7.5
CVE-2012-6571

The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500…

Mitigation only
Fix from $1,950 2013-06-20
C Treeace HIGH 7.1
CVE-2013-0148

The Data Camouflage (aka FairCom Standard Encryption) algorithm in FairCom c-treeACE does not ensure that a decryption key is needed for accessing da…

Mitigation only
Fix from $1,950 2013-06-16
Filemaker Pro MEDIUM 5.8
CVE-2013-2319

FileMaker Pro before 12 and Pro Advanced before 12 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to s…

Fix: after 11.0.4.0
Fix from $1,600 2013-06-10
Pizza Hut Japan Official Order Application MEDIUM 5.8
CVE-2013-3641

The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-th…

Fix: after 1.1.0
Fix from $1,600 2013-06-10
Nx Os MEDIUM 5.8
CVE-2013-1212

The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoo…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.8
CVE-2013-1208

The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (V…

Mitigation only
Fix from $1,600 2013-05-29
Puppet Enterprise MEDIUM 5.0
CVE-2013-2716

Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading fr…

Fix: after 2.7.2
Fix from $1,600 2013-04-10
Ims Enterprise Suite MEDIUM 5.0
CVE-2013-0483

The login component in SOAP Gateway in IBM IMS Enterprise Suite 1.1, 2.1, and 2.2 uses cleartext credentials, which allows remote attackers to obtain…

Mitigation only
Fix from $1,600 2013-04-05
Network Admission Control MEDIUM 5.8
CVE-2013-1124

The Cisco Network Admission Control (NAC) agent on Mac OS X does not verify the X.509 certificate of an Identity Services Engine (ISE) server during …

Mitigation only
Fix from $1,600 2013-02-28
Edr G903 Firmware HIGH 7.6
CVE-2012-4694

Moxa EDR-G903 series routers with firmware before 2.11 do not use a sufficient source of entropy for (1) SSH and (2) SSL keys, which makes it easier …

Fix: after 2.2
Fix from $1,950 2013-02-15
OpenSSL MEDIUM 5.0
CVE-2013-0166EPSS 20%

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows…

Mitigation only
Fix from $1,600 2013-02-08
Freeipa HIGH 7.9
CVE-2012-5484

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows ma…

Mitigation only
Fix from $1,950 2013-01-27
Tripadvisor MEDIUM 5.0
CVE-2012-4917

The TripAdvisor app 6.6 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

Mitigation only
Fix from $1,600 2013-01-26
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2012-0861

The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading d…

Fix: after 3.0
Fix from $1,600 2013-01-04
Mesh Os MEDIUM 6.1
CVE-2012-4898

Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the…

Fix: after 7.9.1
Fix from $1,600 2012-12-18
Helpbox MEDIUM 5.0
CVE-2012-4977

Layton Helpbox 4.4.0 allows remote attackers to discover cleartext credentials for the login page by sniffing the network.

Mitigation only
Fix from $1,600 2012-12-12
Awam Bluetooth Reader HIGH 7.6
CVE-2012-4687

Post Oak AWAM Bluetooth Reader Traffic System does not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-midd…

Mitigation only
Fix from $1,950 2012-12-08
Jruby MEDIUM 5.0
CVE-2012-5370

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers …

Mitigation only
Fix from $1,600 2012-11-28
Ruby MEDIUM 5.0
CVE-2012-5371

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions…

Fix: after 1.9.3
Fix from $1,600 2012-11-28
Rubinius MEDIUM 5.0
CVE-2012-5372

Rubinius computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attacke…

No fix yet
Fix from $1,600 2012-11-28
Openjdk MEDIUM 5.0
CVE-2012-5373

Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions pre…

Fix: after 1.7.0
Fix from $1,600 2012-11-28
Cityhash MEDIUM 5.0
CVE-2012-6051

Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent …

Mitigation only
Fix from $1,600 2012-11-28
Openjdk MEDIUM 5.0
CVE-2012-2739

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to tr…

Fix: after 1.7.0
Fix from $1,600 2012-11-28
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2011-1096

The W3C XML Encryption Standard, as used in the JBoss Web Services (JBossWS) component in JBoss Enterprise Portal Platform before 5.2.2 and other pro…

Fix: after 5.2.1
Fix from $1,600 2012-11-23
Sinapsi Firmware HIGH 10.0
CVE-2012-5862EPSS 12%

These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log i…

Fix: after 2.0.2870
Fix from $1,950 2012-11-23
Fleetcommander MEDIUM 5.0
CVE-2012-4946

Agile FleetCommander and FleetCommander Kiosk before 4.08 use an XOR format for password encryption, which makes it easier for context-dependent atta…

Fix: after 4.0
Fix from $1,600 2012-11-18
Fleetcommander MEDIUM 5.0
CVE-2012-4947

Agile FleetCommander and FleetCommander Kiosk before 4.08 store database credentials in cleartext, which allows remote attackers to obtain sensitive …

Fix: after 4.0
Fix from $1,600 2012-11-18
Groupon Merchants MEDIUM 5.8
CVE-2012-5809

The Groupon Redemptions application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or s…

No fix yet
Fix from $1,600 2012-11-04
Breezy MEDIUM 5.8
CVE-2012-5811

The Breezy application for Android does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName…

No fix yet
Fix from $1,600 2012-11-04