Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Tinyproxy MEDIUM 5.0
CVE-2012-3505EPSS 7%

Tinyproxy 1.8.3 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via (1) a large number of headers or (2…

Fix: after 1.8.3
Fix from $1,600 2012-10-09
Ftp Server MEDIUM 5.0
CVE-2012-5301

The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers …

Fix: after 5.0.3.1
Fix from $1,600 2012-10-04
Enterprise Mrg MEDIUM 5.8
CVE-2012-2681

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session key…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Remote Supervisor Adapter Ii Firmware MEDIUM 5.0
CVE-2012-2187

IBM Remote Supervisor Adapter II firmware for System x3650, x3850 M2, and x3950 M2 1.13 and earlier generates weak RSA keys, which makes it easier fo…

Fix: after 1.13
Fix from $1,600 2012-09-25
Iphone Os MEDIUM 6.4
CVE-2012-3732

Mail in Apple iOS before 6 uses an S/MIME message's From address as the displayed sender address, which allows remote attackers to spoof signed conte…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Silverstripe MEDIUM 5.0
CVE-2010-5079

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 uses weak entropy when generating tokens for (1) the CSRF protection mechanism, (2) autologin…

Patch available
Fix from $1,600 2012-09-17
Ovirt MEDIUM 5.0
CVE-2012-3533

The python SDK before 3.1.0.6 and CLI before 3.1.0.8 for oVirt 3.1 does not check the server SSL certificate against the client keys, which allows re…

Fix: after 3.1.0.5
Fix from $1,600 2012-08-31
Infosphere Guardium MEDIUM 5.0
CVE-2012-3312

The datasource definition editor in IBM InfoSphere Guardium 8.2 and earlier, when the save-password setting is enabled, transmits cleartext database …

Fix: after 8.2
Fix from $1,600 2012-08-29
Comodo Internet Security HIGH 10.0
CVE-2011-5121

The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not properly check whether unspecified X.509 certificates are revoked…

Fix: after 5.3.174622.1216
Fix from $1,950 2012-08-26
Comodo Internet Security HIGH 10.0
CVE-2011-5123

The Antivirus component in Comodo Internet Security before 5.3.175888.1227 does not check whether X.509 certificates in signed executable files have …

Fix: after 5.3.174622.1216
Fix from $1,950 2012-08-26
Ocaml Xml Light Library MEDIUM 5.0
CVE-2012-3514

OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context…

Mitigation only
Fix from $1,600 2012-08-25
Websphere Application Server MEDIUM 5.0
CVE-2012-2190

IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.2…

Mitigation only
Fix from $1,600 2012-08-21
Certificate System MEDIUM 5.5
CVE-2012-3367

Red Hat Certificate System (RHCS) before 8.1.1 and Dogtag Certificate System does not properly check certificate revocation requests made through the…

Fix: after 8.1
Fix from $1,600 2012-08-13
Anyconnect Secure Mobility Client MEDIUM 5.8
CVE-2012-2499

The IPsec implementation in Cisco AnyConnect Secure Mobility Client 3.0 before 3.0.08057 does not verify the certificate name in an X.509 certificate…

Mitigation only
Fix from $1,600 2012-08-06
Airdroid MEDIUM 5.0
CVE-2012-3887

AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which allows r…

Fix: after 1.0.6
Fix from $1,600 2012-07-26
Hadoop HIGH 7.5
CVE-2012-3376

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…

Mitigation only
Fix from $1,950 2012-07-12
Cyberoam Unified Threat Management HIGH 7.4
CVE-2012-3372

The default configuration of Cyberoam UTM appliances uses the same Certification Authority certificate and same private key across different customer…

Mitigation only
Fix from $1,950 2012-07-09
Commons Compress MEDIUM 5.0
CVE-2012-2098EPSS 13%

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress b…

Fix: 1.4.1+
Fix from $1,600 2012-06-29
Mguard Firmware HIGH 7.1
CVE-2012-3006

The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-2110…

Fix: 7.5.0+
Fix from $1,950 2012-06-19
Md5crypt MEDIUM 5.0
CVE-2012-3287

Poul-Henning Kamp md5crypt has insufficient algorithmic complexity and a consequently short runtime, which makes it easier for context-dependent atta…

Mitigation only
Fix from $1,600 2012-06-13
Opera Browser MEDIUM 5.8
CVE-2012-1251

Opera before 9.63 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain …

Fix: after 9.62
Fix from $1,600 2012-06-04
Mac Os X MEDIUM 6.4
CVE-2012-0655

libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for re…

Fix: after 10.7.3
Fix from $1,600 2012-05-11
Rational Appscan MEDIUM 5.8
CVE-2012-0732

The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, whic…

Mitigation only
Fix from $1,600 2012-05-03
Websphere Application Server MEDIUM 6.8
CVE-2012-2162

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-k…

Fix: after 8.0.0.0
Fix from $1,600 2012-05-01
Ruggedcom Rugged Operating System HIGH 8.5
CVE-2012-1803EPSS 49%

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, wh…

Fix: after 3.10.1
Fix from $1,950 2012-04-28
Spmode Mail Android MEDIUM 5.8
CVE-2012-1244

The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SSL servers, which allows man-i…

Fix: after 5400
Fix from $1,600 2012-04-27
Gallery HIGH 10.0
CVE-2012-2405

Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulner…

No fix yet
Fix from $1,950 2012-04-22
Tivoli Directory Server MEDIUM 6.4
CVE-2012-0726

The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allow…

Fix: after 6.3.0
Fix from $1,600 2012-04-22
Hadoop MEDIUM 6.5
CVE-2012-1574

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…

Mitigation only
Fix from $1,600 2012-04-12
Cloudera Manager MEDIUM 6.5
CVE-2012-2230

Cloudera Manager 3.7.x before 3.7.5 and Service and Configuration Manager 3.5, when Kerberos is not enabled, does not properly install taskcontroller…

Mitigation only
Fix from $1,600 2012-04-12