Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
MEDIUM 6.5 CVE-2016-1938 The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, imprope… Firefox after 43.0.4 Fix from $1,6002016-01-31 CRITICAL 9.0 CVE-2015-7923 Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle atta… Weos Mitigation only Fix from $2,3002016-01-30 MEDIUM 6.5 CVE-2016-1618 Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi… Chrome after 47.0.2526.106 Fix from $1,6002016-01-25 HIGH 7.5 CVE-2015-8281 Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations. Web Viewer after 1.0.0.193 Fix from $1,9502016-01-15 HIGH 8.1 CVE-2014-8886EPSS 6% AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to c… Fritz\! Os after 6.23 Fix from $1,9502016-01-08 HIGH 7.5 CVE-2014-3260 Pacom 1000 CCU and RTU GMS devices allow remote attackers to spoof the controller-to-base data stream by leveraging improper use of cryptography. 1000 Ccu Gms Mitigation only Fix from $1,9502015-12-31 MEDIUM 5.0 CVE-2015-7756 The encryption implementation in Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.… Screenos Mitigation only Fix from $1,6002015-12-19 MEDIUM 6.4 CVE-2015-7286 CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hardcoded keys, which makes it ea… Gprs Cs2300 R Firmware No fix yet Fix from $1,6002015-11-25 MEDIUM 5.0 CVE-2015-8329 SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct down… Manufacturing Integration And Intelligence No fix yet Fix from $1,6002015-11-24 MEDIUM 5.8 CVE-2015-6112 SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, … Windows 7 Patch available Fix from $1,6002015-11-11 MEDIUM 5.8 CVE-2015-5655 The Adways Party Track SDK before 1.6.6 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo… Party Track Sdk after 1.6.5 Fix from $1,6002015-11-10 MEDIUM 5.0 CVE-2015-7940 The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obt… Leap after 1.50 Fix from $1,6002015-11-09 MEDIUM 6.8 CVE-2015-2902 HP ArcSight SmartConnectors before 7.1.6 do not verify X.509 certificates from Logger devices, which allows man-in-the-middle attackers to spoof devi… Arcsight Smartconnectors after 7.1.5 Fix from $1,6002015-11-04 HIGH 9.3 CVE-2015-6033 Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass… Iq Panel after 1.5.0 Fix from $1,9502015-10-31 MEDIUM 5.8 CVE-2014-8242 librsync before 1.0.0 uses a truncated MD4 checksum to match blocks, which makes it easier for remote attackers to modify transmitted data via a birt… Librsync 1.0.0+ Fix from $1,6002015-10-26 MEDIUM 5.0 CVE-2015-1934 IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX002, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x befor… Change And Configuration Management Database Patch available Fix from $1,6002015-10-04 MEDIUM 5.8 CVE-2015-6932 VMware vCenter Server 5.5 before u3 and 6.0 before u1 does not verify X.509 certificates from TLS LDAP servers, which allows man-in-the-middle attack… Vcenter Server Mitigation only Fix from $1,6002015-09-18 MEDIUM 5.8 CVE-2015-5717 The Siemens COMPAS Mobile application before 1.6 for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi… Compas after 1.5 Fix from $1,6002015-08-31 MEDIUM 5.0 CVE-2015-1816 Forman before 1.7.4 does not verify SSL certificates for LDAP connections, which allows man-in-the-middle attackers to spoof LDAP servers via a craft… Foreman after 1.7.3 Fix from $1,6002015-08-14 MEDIUM 6.4 CVE-2015-2323 FortiOS 5.0.x before 5.0.12 and 5.2.x before 5.2.4 supports anonymous, export, RC4, and possibly other weak ciphers when using TLS to connect to Fort… Fortios Mitigation only Fix from $1,6002015-08-11 MEDIUM 5.0 CVE-2015-1913 Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.… Rational Test Virtualization Server Patch available Fix from $1,6002015-06-30 MEDIUM 5.8 CVE-2015-2859 Intel McAfee ePolicy Orchestrator (ePO) 4.x through 4.6.9 and 5.x through 5.1.2 does not validate server names and Certification Authority names in X… Epolicy Orchestrator Patch available Fix from $1,6002015-06-23 HIGH 8.8 CVE-2012-4716 N-Tron 702-W Industrial Wireless Access Point devices use the same (1) SSH and (2) HTTPS private keys across different customers' installations, whic… 702w Industrial Wireless Access Point Mitigation only Fix from $1,9502015-06-13 MEDIUM 6.8 CVE-2015-4080 The Kankun Smart Socket device and mobile application uses a hardcoded AES 256 bit key, which makes it easier for remote attackers to (1) obtain sens… Smartsocket No fix yet Fix from $1,6002015-06-09 MEDIUM 6.8 CVE-2015-1848 The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote atta… Pacemaker Configuration System after 0.9.137 Fix from $1,6002015-05-14 MEDIUM 5.0 CVE-2015-1672EPSS 18% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allows remote attackers to cause a denial of service (recursion and performanc… .net Framework Mitigation only Fix from $1,6002015-05-13 HIGH 8.3 CVE-2015-2233 Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which a… System Update after 5.06.0027 Fix from $1,9502015-05-12 MEDIUM 5.4 CVE-2015-3610 The Siemens HomeControl for Room Automation application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows ma… Homecontrol For Room Automation after 2.0.0 Fix from $1,6002015-05-07 MEDIUM 5.0 CVE-2015-3322 Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passw… Thinkserver Rd650 Firmware after 1.25.0 Fix from $1,6002015-04-16 HIGH 9.4 CVE-2014-6221 The MSCAPI/MSCNG interface implementation in GSKit in IBM Rational ClearCase 7.1.2.x before 7.1.2.17, 8.0.0.x before 8.0.0.14, and 8.0.1.x before 8.0… Rational Clearcase Patch available Fix from $1,9502015-04-06