Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Crypto HIGH 8.1
CVE-2017-3204

The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4…

Fix: after 2017-03-17
Fix from $1,950 2017-04-04
Mac Os X MEDIUM 6.8
CVE-2016-7585

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It…

Fix: after 10.12.3
Fix from $1,600 2017-04-02
Glance MEDIUM 5.5
CVE-2015-8234

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, wh…

Patch available
Fix from $1,600 2017-03-29
Vulnerability Manager HIGH 8.8
CVE-2015-8989

Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earli…

Fix: after 7.5.8
Fix from $1,950 2017-03-14
Vce Vision Intelligent Operations MEDIUM 6.7
CVE-2015-4056

The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users …

Fix: after 2.6.4
Fix from $1,600 2017-02-21
Miineport E1 Firmware MEDIUM 5.3
CVE-2016-9346

An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. Configuration data are st…

Fix: after 1.7
Fix from $1,600 2017-02-13
Openvpn MEDIUM 5.9
CVE-2016-6329EPSS 6%

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duratio…

Fix: after 2.3.14
Fix from $1,600 2017-01-31
Adups Fota HIGH 7.8
CVE-2016-10136

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in…

Mitigation only
Fix from $1,950 2017-01-13
Adups Fota HIGH 7.8
CVE-2016-10137

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in…

Mitigation only
Fix from $1,950 2017-01-13
Adups Fota HIGH 7.8
CVE-2016-10138

An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a syste…

Mitigation only
Fix from $1,950 2017-01-13
Adups Fota HIGH 7.8
CVE-2016-10139

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and …

Mitigation only
Fix from $1,950 2017-01-13
Borg MEDIUM 5.3
CVE-2016-10099

Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowin…

Fix: after 1.0.8
Fix from $1,600 2017-01-02
.net Framework HIGH 7.5
CVE-2016-7270EPSS 20%

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the A…

Mitigation only
Fix from $1,950 2016-12-20
Content Security Management Appliance MEDIUM 5.9
CVE-2016-1411

A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), a…

Mitigation only
Fix from $1,600 2016-12-14
Wolfssl MEDIUM 5.5
CVE-2016-7439

The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…

Fix: after 3.9.8
Fix from $1,600 2016-12-13
Wolfssl MEDIUM 5.5
CVE-2016-7438

The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…

Fix: after 3.9.8
Fix from $1,600 2016-12-13
phpMyAdmin MEDIUM 5.3
CVE-2016-9847

An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runti…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6606

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca…

Patch available
Fix from $1,950 2016-12-11
Bitcoin Knots MEDIUM 6.2
CVE-2016-8889

In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information i…

Patch available
Fix from $1,600 2016-10-28
Onetouch Ping Firmware HIGH 7.5
CVE-2016-5084

Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive informa…

Mitigation only
Fix from $1,950 2016-10-05
The U MEDIUM 5.4
CVE-2016-6550

The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to…

Fix: after 1.5.4
Fix from $1,600 2016-10-05
Security Privileged Identity Manager Virtual Appliance HIGH 7.5
CVE-2016-5957

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection me…

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Safari MEDIUM 6.8
CVE-2016-4763

WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HT…

Fix: after 12.4.3
Fix from $1,600 2016-09-25
Os X Server HIGH 7.5
CVE-2016-4754

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mech…

Fix: after 5.1
Fix from $1,950 2016-09-25
Avamar Server HIGH 8.6
CVE-2016-0904

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers…

Fix: after 7.3.0
Fix from $1,950 2016-09-21
Operations Manager CRITICAL 9.8
CVE-2016-0897

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for…

Fix: after 1.6.16
Fix from $2,300 2016-09-18
Rh5885 V3 Server Firmware HIGH 7.5
CVE-2016-6899

The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with sof…

Mitigation only
Fix from $1,950 2016-09-07
Rh1288 V3 Server Firmware HIGH 7.5
CVE-2016-6838

Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers…

Mitigation only
Fix from $1,950 2016-09-07
Jose Php MEDIUM 5.3
CVE-2016-5430

The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which m…

Fix: 2.2.1+
Fix from $1,600 2016-09-03
Debian Linux HIGH 7.5
CVE-2016-5419EPSS 16%

curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass…

Fix: after 7.50.0
Fix from $1,950 2016-08-10