Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Firefox MEDIUM 5.8
CVE-2010-3399

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a conte…

No fix yet
Fix from $1,600 2010-09-15
Firefox MEDIUM 5.8
CVE-2010-3400

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5…

Fix: after 2.0.4
Fix from $1,600 2010-09-15
Bugzilla MEDIUM 6.5
CVE-2010-2757

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonat…

Mitigation only
Fix from $1,600 2010-08-16
Unified Wireless Network Solution Software HIGH 10.0
CVE-2010-2978

Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, wh…

Mitigation only
Fix from $1,950 2010-08-10
Vxworks HIGH 7.8
CVE-2010-2967

The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, …

Fix: after 6.8
Fix from $1,950 2010-08-05
Netbox HIGH 10.0
CVE-2010-2468

The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Adm…

No fix yet
Fix from $1,950 2010-06-25
Mac Os X HIGH 9.3
CVE-2010-1377

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attac…

Patch available
Fix from $1,950 2010-06-17
Rock Web Server HIGH 7.5
CVE-2010-2270

Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sess…

No fix yet
Fix from $1,950 2010-06-15
Safari MEDIUM 5.0
CVE-2010-1413

WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, sends NTLM credentials in cleartext in …

Fix: after 4.0.5
Fix from $1,600 2010-06-11
Gnutls MEDIUM 5.0
CVE-2006-7239

The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (c…

Fix: after 1.4.1
Fix from $1,600 2010-05-24
Ironport Desktop Flag Plugin For Outlook MEDIUM 5.0
CVE-2010-1568

The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously compose…

Fix: after 6.5.0
Fix from $1,600 2010-05-14
Consona Dynamic Agent HIGH 7.2
CVE-2010-1906

tgsrv.exe in the Repair Service in Consona Dynamic Agent, Repair Manager, Subscriber Activation, and Subscriber Agent relies on a predictable timesta…

Patch available
Fix from $1,950 2010-05-12
Consona Dynamic Agent HIGH 9.3
CVE-2010-1911

The site-locking implementation in the SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance…

Patch available
Fix from $1,950 2010-05-12
Windows 2000 MEDIUM 6.4
CVE-2010-1689EPSS 7%

The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003…

Mitigation only
Fix from $1,600 2010-05-07
Virtualiq MEDIUM 5.0
CVE-2009-4845

The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2010-05-07
Tandberg Video Communication Server HIGH 8.5
CVE-2009-4510

The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to cond…

Patch available
Fix from $1,950 2010-04-13
Libesmtp MEDIUM 6.8
CVE-2010-1192

libESMTP, probably 1.0.4 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 …

Fix: after 1.0.4
Fix from $1,600 2010-03-31
Libesmtp MEDIUM 6.8
CVE-2010-1194

The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a…

Patch available
Fix from $1,600 2010-03-31
Mac Os X MEDIUM 5.0
CVE-2010-0525

Mail in Apple Mac OS X before 10.6.3 does not properly enforce the key usage extension during processing of a keychain that specifies multiple certif…

Fix: after 10.6.2
Fix from $1,600 2010-03-30
27mhz Wireless Keyboard HIGH 7.6
CVE-2010-1184EPSS 8%

The Microsoft wireless keyboard uses XOR encryption with a key derived from the MAC address, which makes it easier for remote attackers to obtain key…

No fix yet
Fix from $1,950 2010-03-29
iOS HIGH 7.8
CVE-2010-0578

The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service …

Patch available
Fix from $1,950 2010-03-25
Edirectory HIGH 7.5
CVE-2009-4655EPSS 50%

The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sessions via…

No fix yet
Fix from $1,950 2010-02-26
Windows 2000 HIGH 10.0
CVE-2010-0231EPSS 41%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Zeus Web Server MEDIUM 5.0
CVE-2010-0362

Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.

Fix: after 4.3
Fix from $1,600 2010-01-20
phpMyAdmin HIGH 10.0
CVE-2008-7252

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vect…

Patch available
Fix from $1,950 2010-01-19
Sendmail HIGH 7.5
CVE-2009-4565

sendmail before 8.14.4 does not properly handle a '\0' character in a Common Name (CN) field of an X.509 certificate, which (1) allows man-in-the-mid…

Fix: after 8.14.3
Fix from $1,950 2010-01-04
Networkmanager MEDIUM 6.8
CVE-2009-4144

NetworkManager (NM) 0.7.2 does not ensure that the configured Certification Authority (CA) certificate file for a (1) WPA Enterprise or (2) 802.1x ne…

Mitigation only
Fix from $1,600 2009-12-23
Moodle MEDIUM 5.0
CVE-2009-4302

login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an H…

Patch available
Fix from $1,600 2009-12-16
PostgreSQL MEDIUM 5.8
CVE-2009-4034

PostgreSQL 7.4.x before 7.4.27, 8.0.x before 8.0.23, 8.1.x before 8.1.19, 8.2.x before 8.2.15, 8.3.x before 8.3.9, and 8.4.x before 8.4.2 does not pr…

Patch available
Fix from $1,600 2009-12-15
Ray Server Software HIGH 7.8
CVE-2009-4295

Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which…

Patch available
Fix from $1,950 2009-12-11