Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Phenotype Cms HIGH 7.5
CVE-2009-2951

Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine…

Fix: after 2.8
Fix from $1,950 2009-08-24
Aruba Mobility Controller HIGH 10.0
CVE-2008-7023

Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, w…

Mitigation only
Fix from $1,950 2009-08-21
Gigaset Wlan Camera HIGH 10.0
CVE-2008-6993

Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the proven…

Mitigation only
Fix from $1,950 2009-08-19
Libcurl HIGH 7.5
CVE-2009-2417

lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject'…

Patch available
Fix from $1,950 2009-08-14
Gnutls HIGH 7.5
CVE-2009-2730

libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alte…

Fix: after 2.8.1
Fix from $1,950 2009-08-12
Fetchmail MEDIUM 6.4
CVE-2009-2666

socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 ce…

Fix: after 6.3.10
Fix from $1,600 2009-08-07
Services MEDIUM 6.5
CVE-2008-6909

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact,…

Patch available
Fix from $1,600 2009-08-06
Services HIGH 7.5
CVE-2008-6910

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers t…

Patch available
Fix from $1,950 2009-08-06
Services HIGH 7.5
CVE-2008-6908

Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers…

Patch available
Fix from $1,950 2009-08-06
Strongswan MEDIUM 5.0
CVE-2009-2661

The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with cr…

Patch available
Fix from $1,600 2009-08-04
Mv 410r MEDIUM 5.0
CVE-2009-2319

The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtai…

Mitigation only
Fix from $1,600 2009-07-05
Firefox HIGH 9.3
CVE-2009-2061

Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to ex…

Fix: after 3.0.9
Fix from $1,950 2009-06-15
Safari MEDIUM 5.0
CVE-2009-1696

WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav…

Fix: after 4.0_beta
Fix from $1,600 2009-06-10
Wl54ap2 HIGH 10.0
CVE-2008-6824

The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier fo…

Patch available
Fix from $1,950 2009-06-04
Kh1516i Ip Kvm Switch HIGH 10.0
CVE-2009-1472

The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded A…

Mitigation only
Fix from $1,950 2009-05-27
Kh1516i Ip Kvm Switch HIGH 10.0
CVE-2009-1473

The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.…

Mitigation only
Fix from $1,950 2009-05-27
Kh1516i Ip Kvm Switch HIGH 7.6
CVE-2009-1474

The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes …

Mitigation only
Fix from $1,950 2009-05-27
Kh1516i Ip Kvm Switch HIGH 10.0
CVE-2009-1477

The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 powe…

Mitigation only
Fix from $1,950 2009-05-27
Mitel Nupoint Messenger HIGH 7.8
CVE-2008-6797

The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt…

Mitigation only
Fix from $1,950 2009-05-07
Linux MEDIUM 5.0
CVE-2008-6792

system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES…

Mitigation only
Fix from $1,600 2009-05-07
Wvc54gc HIGH 7.8
CVE-2009-1560

The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pas…

No fix yet
Fix from $1,950 2009-05-06
Gnutls HIGH 7.5
CVE-2009-1416

lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might…

Patch available
Fix from $1,950 2009-04-30
Gnutls MEDIUM 5.0
CVE-2009-1417

gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to success…

Fix: after 2.6.5
Fix from $1,600 2009-04-30
Glfusion MEDIUM 6.8
CVE-2009-1283

glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privile…

Fix: after 1.1.2
Fix from $1,600 2009-04-09
Websphere Application Server HIGH 10.0
CVE-2009-1174

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "securi…

Patch available
Fix from $1,950 2009-03-31
Java System Identity Manager MEDIUM 5.0
CVE-2009-1074

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to …

Patch available
Fix from $1,600 2009-03-25
Application Control Engine Module HIGH 7.8
CVE-2009-0742

The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro…

Patch available
Fix from $1,950 2009-02-26
Myblog MEDIUM 5.0
CVE-2008-6193

Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

No fix yet
Fix from $1,600 2009-02-19
Evolution MEDIUM 5.0
CVE-2009-0547

Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to…

Mitigation only
Fix from $1,600 2009-02-12
Gale MEDIUM 5.0
CVE-2009-0047

Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass val…

Fix: after 0.99
Fix from $1,600 2009-01-07