Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
iOS HIGH 7.5
CVE-2012-0381

The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S,…

Fix: 3.2.2sg / 3.4.1s+
Fix from $1,950 2012-03-29
iOS HIGH 7.8
CVE-2012-0386

The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows …

Mitigation only
Fix from $1,950 2012-03-29
Gnutls MEDIUM 5.0
CVE-2012-1573

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows…

Fix: after 2.12.16
Fix from $1,600 2012-03-26
Glib HIGH 7.5
CVE-2012-0039

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predic…

Fix: after 2.31.8
Fix from $1,950 2012-01-14
Sun Storage Common Array Manager MEDIUM 5.3
CVE-2011-4461

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which al…

Fix: after 8.1.0
Fix from $1,600 2011-12-30
Rack MEDIUM 5.0
CVE-2011-5036

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger has…

Fix: after 1.1.0
Fix from $1,600 2011-12-30
Parallels Plesk Small Business Panel MEDIUM 5.0
CVE-2011-4758

Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive informatio…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4746

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for remote attack…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4747

The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL sessions, which makes it easi…

Mitigation only
Fix from $1,600 2011-12-16
Parallels Plesk Panel MEDIUM 5.0
CVE-2011-4736

The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obt…

Mitigation only
Fix from $1,600 2011-12-16
Opera Browser HIGH 10.0
CVE-2011-4684EPSS 6%

Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

Fix: after 11.60
Fix from $1,950 2011-12-07
Joomla\! MEDIUM 5.0
CVE-2011-4321

The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the p…

Mitigation only
Fix from $1,600 2011-11-23
Dir 685 HIGH 7.5
CVE-2011-4507EPSS 6%

The D-Link DIR-685 router, when certain WPA and WPA2 configurations are used, does not maintain an encrypted wireless network during transfer of a la…

Mitigation only
Fix from $1,950 2011-11-22
Kace K2000 Systems Deployment Appliance MEDIUM 5.0
CVE-2011-4046

The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent…

Mitigation only
Fix from $1,600 2011-11-12
Centreon MEDIUM 5.0
CVE-2011-4432

www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password ha…

Fix: after 2.3.1
Fix from $1,600 2011-11-10
Crypt Dsa MEDIUM 5.8
CVE-2011-3599

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for …

Fix: after 1.17
Fix from $1,600 2011-10-10
Servicedesk Plus MEDIUM 5.0
CVE-2011-1509

The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in …

Fix: after 8012
Fix from $1,600 2011-09-20
Envision MEDIUM 5.0
CVE-2011-2736

RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obt…

Mitigation only
Fix from $1,600 2011-08-25
PHP MEDIUM 5.0
CVE-2011-2483

crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-…

Fix: 1.1 / 5.3.7+
Fix from $1,600 2011-08-25
Data Synchronizer MEDIUM 5.0
CVE-2011-3013

WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for…

Mitigation only
Fix from $1,600 2011-08-09
Data Synchronizer MEDIUM 5.0
CVE-2011-2223

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote …

Mitigation only
Fix from $1,600 2011-08-09
Ruby MEDIUM 5.0
CVE-2011-3009

Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of ra…

Fix: after 1.8.6
Fix from $1,600 2011-08-05
Ruby MEDIUM 5.0
CVE-2011-2686

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of ra…

Fix: after 1.8.7-334
Fix from $1,600 2011-08-05
Safari MEDIUM 5.0
CVE-2011-0214

CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote w…

Fix: after 5.0.5
Fix from $1,600 2011-07-21
Android HIGH 10.0
CVE-2011-2344

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which al…

Mitigation only
Fix from $1,950 2011-07-08
Mac Os X MEDIUM 5.0
CVE-2011-0207

The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows re…

Patch available
Fix from $1,600 2011-06-24
Smf HIGH 7.5
CVE-2011-1128

The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid logi…

Fix: after 1.1.12
Fix from $1,950 2011-06-21
Crypto HIGH 7.8
CVE-2011-0766

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses…

Fix: after 2.0.4
Fix from $1,950 2011-05-31
Smarterstats MEDIUM 5.0
CVE-2011-2151

The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser.aspx, and (5) Login.aspx com…

Mitigation only
Fix from $1,600 2011-05-20
Chat Server MEDIUM 5.8
CVE-2010-0217

Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions …

Fix: after 5.0
Fix from $1,600 2011-05-20