Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Motorola Phone Adapter Vt2142 Vd HIGH 7.1
CVE-2007-5792

The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network an…

Mitigation only
Fix from $1,950 2007-11-01
Globe7 MEDIUM 5.0
CVE-2007-5768

The Globe7 soft phone client 7.3 sends username and password information in cleartext, which allows remote attackers to obtain sensitive information …

Mitigation only
Fix from $1,600 2007-10-31
Suse Linux MEDIUM 6.8
CVE-2007-5195

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Patch available
Fix from $1,600 2007-10-14
Suse Linux HIGH 7.5
CVE-2007-5196

Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto…

Mitigation only
Fix from $1,950 2007-10-14
Second Life MEDIUM 5.0
CVE-2007-4960

Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, all…

Mitigation only
Fix from $1,600 2007-09-18
Remotedocs R Viewer HIGH 9.3
CVE-2007-4750

Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ ar…

Fix: after 1.6.2836
Fix from $1,950 2007-09-18
207w Camera HIGH 9.3
CVE-2007-4926

The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive info…

Mitigation only
Fix from $1,950 2007-09-18
Weblogic Server MEDIUM 6.8
CVE-2007-4613

SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plai…

Patch available
Fix from $1,600 2007-08-31
Linux Kernel MEDIUM 6.8
CVE-2007-4311

The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few byte…

Fix: after 2.4.34
Fix from $1,600 2007-08-13
Clavister Coreplus MEDIUM 5.4
CVE-2007-3805

The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allow…

Fix: after 8.80.03
Fix from $1,600 2007-07-16
Seleniumserver Ftp Server HIGH 10.0
CVE-2006-5982

SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to obtain pa…

Mitigation only
Fix from $1,950 2006-11-20
Database Server HIGH 10.0
CVE-2006-0270

Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and att…

Mitigation only
Fix from $1,950 2006-01-18
Virus Control System MEDIUM 5.0
CVE-2003-1344

Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive informati…

No fix yet
Fix from $1,600 2003-12-31
Cryptobuddy HIGH 7.5
CVE-2003-1389

RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing…

Mitigation only
Fix from $1,950 2003-12-31
Cryptobuddy HIGH 7.5
CVE-2003-1390

RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the p…

Mitigation only
Fix from $1,950 2003-12-31
Cryptobuddy HIGH 7.5
CVE-2003-1391

RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers t…

Mitigation only
Fix from $1,950 2003-12-31
Cryptobuddy MEDIUM 6.6
CVE-2003-1392

CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decry…

Mitigation only
Fix from $1,600 2003-12-31
Flashfxp MEDIUM 6.4
CVE-2003-1483

FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access.

No fix yet
Fix from $1,600 2003-12-31
iOS MEDIUM 5.0
CVE-2003-0512

Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allo…

Mitigation only
Fix from $1,600 2003-08-27
Shopfactory HIGH 7.8
CVE-2002-2303

3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart pr…

Mitigation only
Fix from $1,950 2002-12-31
Mac Os X MEDIUM 5.0
CVE-2002-2326

The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext whe…

Mitigation only
Fix from $1,600 2002-12-31
As5350 HIGH 7.8
CVE-2002-2379EPSS 6%

Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of servic…

No fix yet
Fix from $1,950 2002-12-31
Serv U File Server HIGH 7.5
CVE-2001-1463

The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…

No fix yet
Fix from $1,950 2001-11-19
Ssh HIGH 7.5
CVE-2001-1473EPSS 6%

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a…

Mitigation only
Fix from $1,950 2001-01-18
Sawmill HIGH 7.5
CVE-2000-0589

SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration.

Patch available
Fix from $1,950 2000-06-26