Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Md5 CRITICAL 9.8
CVE-2004-2761EPSS 10%

The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as de…

Patch available
Fix from $2,300 2009-01-05
Classpath HIGH 7.5
CVE-2008-5659

The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for…

Fix: after 0.97.2
Fix from $1,950 2008-12-17
Solaris HIGH 7.8
CVE-2008-5410

The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which …

Patch available
Fix from $1,950 2008-12-10
Websphere Application Server MEDIUM 5.0
CVE-2008-5411

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain …

Fix: after 7.0
Fix from $1,600 2008-12-10
Acrobat HIGH 7.5
CVE-2008-5331

Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute…

Mitigation only
Fix from $1,950 2008-12-05
Oempro MEDIUM 5.0
CVE-2008-3057

Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes i…

No fix yet
Fix from $1,600 2008-12-03
Iphone Os HIGH 7.5
CVE-2008-4227

Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th…

Mitigation only
Fix from $1,950 2008-11-25
iOS MEDIUM 6.8
CVE-2008-5230

The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi…

No fix yet
Fix from $1,600 2008-11-25
.net Framework HIGH 10.0
CVE-2008-5100EPSS 8%

The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname o…

No fix yet
Fix from $1,950 2008-11-17
Mac Os X MEDIUM 5.0
CVE-2008-4368

The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE…

Mitigation only
Fix from $1,600 2008-10-01
Squirrelmail MEDIUM 5.0
CVE-2008-3663

Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a…

Mitigation only
Fix from $1,600 2008-09-24
Mantisbt MEDIUM 5.0
CVE-2008-3102

Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the coo…

Mitigation only
Fix from $1,600 2008-09-24
Gallery MEDIUM 5.0
CVE-2008-3662

Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be…

Fix: after 2.2.5
Fix from $1,600 2008-09-18
True Image Echo Server MEDIUM 5.0
CVE-2008-3671

Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain se…

No fix yet
Fix from $1,600 2008-08-13
Pidgin MEDIUM 6.8
CVE-2008-3532

The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepti…

Patch available
Fix from $1,600 2008-08-08
Dantz Retrospect Backup Server MEDIUM 5.0
CVE-2008-3288

The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-depend…

Patch available
Fix from $1,600 2008-07-24
Websphere Application Server MEDIUM 5.0
CVE-2008-3236

Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo…

Mitigation only
Fix from $1,600 2008-07-21
Anubis Plugin MEDIUM 6.4
CVE-2008-2780

The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, wh…

Fix: after 1.2
Fix from $1,600 2008-06-19
Cre Loaded MEDIUM 5.0
CVE-2008-2558

CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff…

Fix: after 6.2.13.1
Fix from $1,600 2008-06-05
Linux MEDIUM 5.0
CVE-2008-2285

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier fo…

Mitigation only
Fix from $1,600 2008-05-18
Presentation Server MEDIUM 5.0
CVE-2008-2299

Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and…

Fix: after 4.5
Fix from $1,600 2008-05-18
Download Client HIGH 7.5
CVE-2008-1886EPSS 7%

The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauth…

No fix yet
Fix from $1,950 2008-04-18
Socialware MEDIUM 5.0
CVE-2008-1772

iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information.

No fix yet
Fix from $1,600 2008-04-14
Advanced Web Photo Gallery MEDIUM 5.0
CVE-2008-1711

Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attac…

No fix yet
Fix from $1,600 2008-04-09
Prestige 660 HIGH 7.5
CVE-2008-1527

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication …

Mitigation only
Fix from $1,950 2008-03-26
Extremez Ip File Server MEDIUM 5.0
CVE-2008-0759

ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an …

Fix: after 5.1.2
Fix from $1,600 2008-02-13
Faqmasterflexplus MEDIUM 6.4
CVE-2007-6635

FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context-dependent attackers to obtai…

No fix yet
Fix from $1,600 2008-01-04
Opera Browser HIGH 10.0
CVE-2007-6521EPSS 5%

Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.

Fix: after 9.24
Fix from $1,950 2007-12-24
Mac Os X HIGH 9.3
CVE-2007-5863EPSS 23%

Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie…

Mitigation only
Fix from $1,950 2007-12-19
Fips Object Module MEDIUM 6.4
CVE-2007-5502

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data…

Patch available
Fix from $1,600 2007-12-01