Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Websphere Application Server MEDIUM 6.4
CVE-2009-2749

Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session value…

Fix: after 1.0
Fix from $1,600 2009-12-08
Mac Os X MEDIUM 5.0
CVE-2009-2843

Java for Mac OS X 10.5 before Update 6 and 10.6 before Update 1 accepts expired certificates for applets, which makes it easier for remote attackers …

Patch available
Fix from $1,600 2009-12-08
Mpop MEDIUM 5.0
CVE-2009-3941

Martin Lambers mpop before 1.0.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name …

Fix: after 1.0.18
Fix from $1,600 2009-11-16
Msmtp MEDIUM 6.4
CVE-2009-3942

Martin Lambers msmtp before 1.4.19, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name…

Fix: after 1.4.18
Fix from $1,600 2009-11-16
Online Plug In For Mac MEDIUM 5.8
CVE-2009-3936

Unspecified vulnerability in Citrix Online Plug-in for Windows 11.0.x before 11.0.150 and 11.x before 11.2, Online Plug-in for Mac before 11.0, Recei…

Fix: after 11.2
Fix from $1,600 2009-11-13
Mac Os X MEDIUM 5.4
CVE-2009-2808

Help Viewer in Apple Mac OS X before 10.6.2 does not use an HTTPS connection to retrieve Apple Help content from a web site, which allows man-in-the-…

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Jdk MEDIUM 5.0
CVE-2009-3875

The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update …

Patch available
Fix from $1,600 2009-11-05
Proftpd MEDIUM 5.8
CVE-2009-3639EPSS 6%

The mod_tls module in ProFTPD before 1.3.2b, and 1.3.3 before 1.3.3rc2, when the dNSNameRequired TLS option is enabled, does not properly handle a '\…

Fix: after 1.3.2
Fix from $1,600 2009-10-28
Mutt MEDIUM 6.8
CVE-2009-3765

mutt_ssl.c in mutt 1.5.19 and 1.5.20, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (…

Mitigation only
Fix from $1,600 2009-10-23
Mutt MEDIUM 6.8
CVE-2009-3766

mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject's Common Name (CN) f…

Fix: 1.5.19+
Fix from $1,600 2009-10-23
Acrobat HIGH 9.3
CVE-2009-2982

An unspecified certificate in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might allow remote attackers …

Fix: after 9.1.3
Fix from $1,950 2009-10-19
Windows 2000 MEDIUM 6.8
CVE-2009-2510EPSS 5%

The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Ser…

Mitigation only
Fix from $1,600 2009-10-14
Unbound HIGH 7.5
CVE-2009-3602

Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgrade…

Fix: after 1.3.3
Fix from $1,950 2009-10-13
Pi Server MEDIUM 6.4
CVE-2009-0209

PI Server in OSIsoft PI System before 3.4.380.x does not properly use encryption in the default authentication process, which allows remote attackers…

Fix: after 3.4.375.99
Fix from $1,600 2009-10-01
Wget MEDIUM 6.8
CVE-2009-3490

GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in…

Fix: after 1.11.4
Fix from $1,600 2009-09-30
Opensaml HIGH 7.5
CVE-2009-3474

OpenSAML 2.x before 2.2.1 and XMLTooling 1.x before 1.2.1, as used by Internet2 Shibboleth Service Provider 2.x before 2.2.1, do not follow the KeyDe…

Patch available
Fix from $1,950 2009-09-29
Shibboleth Sp HIGH 7.5
CVE-2009-3475

Internet2 Shibboleth Service Provider software 1.3.x before 1.3.3 and 2.x before 2.2.1, when using PKIX trust validation, does not properly handle a …

Mitigation only
Fix from $1,950 2009-09-29
Blackberry Device Software MEDIUM 6.8
CVE-2009-3477

The Blackberry Browser in RIM BlackBerry Device Software 4.5.0 before 4.5.0.173, 4.6.0 before 4.6.0.303, 4.6.1 before 4.6.1.309, 4.7.0 before 4.7.0.1…

Mitigation only
Fix from $1,600 2009-09-29
Safari HIGH 7.5
CVE-2009-3455

Apple Safari, possibly before 4.0.3, on Mac OS X does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field o…

Fix: after 4.0.2
Fix from $1,950 2009-09-29
Chrome HIGH 7.5
CVE-2009-3456

Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of…

Fix: after 3.0.195.21
Fix from $1,950 2009-09-29
Ts 239 Pro Turbo Nas MEDIUM 5.9
CVE-2009-3200

The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 create an undocumented recovery key and store it in the ENCK …

No fix yet
Fix from $1,600 2009-09-21
Iphone Os HIGH 7.5
CVE-2009-3273

iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof…

Mitigation only
Fix from $1,950 2009-09-21
Kdelibs HIGH 7.5
CVE-2009-2702

KDE KSSL in kdelibs 3.5.4, 4.2.4, and 4.3 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.50…

Mitigation only
Fix from $1,950 2009-09-08
Opera Browser MEDIUM 5.0
CVE-2009-3045

Opera before 10.00 trusts root X.509 certificates signed with the MD2 algorithm, which makes it easier for man-in-the-middle attackers to spoof arbit…

Fix: after 10.00
Fix from $1,600 2009-09-02
Opera Browser MEDIUM 5.0
CVE-2009-3044

Opera before 10.00 does not properly handle a (1) '\0' character or (2) invalid wildcard character in a domain name in the subject's Common Name (CN)…

Fix: after 10.00
Fix from $1,600 2009-09-02
Eye Fi Manager MEDIUM 5.0
CVE-2008-7138

The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and …

Mitigation only
Fix from $1,600 2009-09-01
Pidgin MEDIUM 5.0
CVE-2009-3026

protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting t…

Patch available
Fix from $1,600 2009-08-31
Scanner File Utility MEDIUM 6.4
CVE-2008-7113

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 uses a small space of predictable user identification numbers for access control…

Mitigation only
Fix from $1,600 2009-08-28
Chrome MEDIUM 6.4
CVE-2009-2973

Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, wh…

Fix: after 2.0.172.37
Fix from $1,600 2009-08-27
Aironet Ap1100 HIGH 7.8
CVE-2009-2976

Cisco Aironet Lightweight Access Point (AP) devices send the contents of certain multicast data frames in cleartext, which allows remote attackers to…

Mitigation only
Fix from $1,950 2009-08-27