Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
MEDIUM 5.0 CVE-2014-5403 Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to… Mednet after 5.8 Fix from $1,6002015-04-03 MEDIUM 5.0 CVE-2015-0282 GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote … Gnutls after 3.0.9 Fix from $1,6002015-03-24 MEDIUM 5.0 CVE-2015-2091 The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is … Mod Gnutls after 0.5.1 Fix from $1,6002015-03-13 HIGH 7.5 CVE-2014-3691 Smart Proxy (aka Smart-Proxy and foreman-proxy) in Foreman before 1.5.4 and 1.6.x before 1.6.2 does not validate SSL certificates, which allows remot… Openstack after 1.5.3 Fix from $1,9502015-03-09 MEDIUM 5.8 CVE-2015-1596 The Siemens SPCanywhere application for Android and iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle … Spcanywhere after 1.4.1 Fix from $1,6002015-03-07 MEDIUM 5.0 CVE-2015-2078 The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qu… Redirector Sdk No fix yet Fix from $1,6002015-02-24 MEDIUM 5.0 CVE-2015-1358 The remote-management module in the (1) Multi Panels, (2) Comfort Panels, and (3) RT Advanced functionality in Siemens SIMATIC WinCC (TIA Portal) bef… Wincc Mitigation only Fix from $1,6002015-02-18 HIGH 7.1 CVE-2015-1454 Blue Coat ProxyClient before 3.3.3.3 and 3.4.x before 3.4.4.10 and Unified Agent before 4.1.3.151952 does not properly validate certain certificates,… Proxyclient 3.3.3.3 / 3.4.4.10+ Fix from $1,9502015-02-02 MEDIUM 5.0 CVE-2015-1453 The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers t… Forticlient after 5.2.3.091 Fix from $1,6002015-02-02 MEDIUM 5.8 CVE-2014-8918 IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-mi… Security Appscan Mitigation only Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2014-6136 IBM Security AppScan Standard 8.x and 9.x before 9.0.1.1 FP1 supports unencrypted sessions, which allows remote attackers to obtain sensitive informa… Security Appscan Mitigation only Fix from $1,6002015-02-02 MEDIUM 6.8 CVE-2014-8840 The iTunes Store component in Apple iOS before 8.1.3 allows remote attackers to bypass a Safari sandbox protection mechanism by leveraging redirectio… Iphone Os after 8.1.2 Fix from $1,6002015-01-30 MEDIUM 5.0 CVE-2013-7252 kwalletd in KWallet before KDE Applications 14.12.0 uses Blowfish with ECB mode instead of CBC mode when encrypting the password store, which makes i… Kde Applications after 14.11.3 Fix from $1,6002015-01-18 MEDIUM 5.0 CVE-2014-5419 GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2.1 and earlier and Multilink ML810, ML3000, and ML3100 switches with firmwar… Multilink Ml3100 Firmware after 5.2.0 Fix from $1,6002015-01-17 MEDIUM 5.0 CVE-2014-5386 The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the rand… Hiphop Virtual Machine after 3.2.0 Fix from $1,6002014-12-28 MEDIUM 5.0 CVE-2013-4442 Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dep… Pwgen after 2.06 Fix from $1,6002014-12-19 MEDIUM 5.0 CVE-2014-6087 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier… Security Access Manager For Web Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-6084 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 make it easier… Security Access Manager For Mobile Mitigation only Fix from $1,6002014-12-18 HIGH 9.3 CVE-2014-6140EPSS 6% IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations… Tivoli Endpoint Manager Mobile Device Management after 9.0 Fix from $1,9502014-12-06 MEDIUM 6.8 CVE-2014-9037 WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle… WordPress after 3.7.4 Fix from $1,6002014-11-25 MEDIUM 5.0 CVE-2014-8627 PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified… Polarssl Mitigation only Fix from $1,6002014-11-24 MEDIUM 5.0 CVE-2014-3620 cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a … Curl after 10.10.4 Fix from $1,6002014-11-18 MEDIUM 5.0 CVE-2014-3613EPSS 7% cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send… Curl after 10.10.4 Fix from $1,6002014-11-18 HIGH 10.0 CVE-2014-7878EPSS 10% The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node image, uses… Helion Cloud Development Platform Mitigation only Fix from $1,9502014-11-14 MEDIUM 5.0 CVE-2014-8564 The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote att… Enterprise Linux Desktop Patch available Fix from $1,6002014-11-13 HIGH 7.5 CVE-2014-8587 SAPCRYPTOLIB before 5.555.38, SAPSECULIB, and CommonCryptoLib before 8.4.30, as used in SAP NetWeaver AS for ABAP and SAP HANA, allows remote attacke… Commoncryptolib after 8.4.29 Fix from $1,9502014-11-04 HIGH 7.5 CVE-2014-7228EPSS 55% Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professi… Joomla\! No fix yet Fix from $1,9502014-11-03 MEDIUM 5.0 CVE-2012-6661 Zope before 2.13.19, as used in Plone before 4.2.3 and 4.3 before beta 1, does not reseed the pseudo-random number generator (PRNG), which makes it e… Plone after 4.2.2 Fix from $1,6002014-11-03 MEDIUM 5.0 CVE-2014-8495 Citrix XenMobile MDX Toolkit before 9.0.4, when used to wrap iOS 8 applications, does not properly encrypt cached application data, which allows cont… Xenmobile after 9.0.3 Fix from $1,6002014-10-31 MEDIUM 5.4 CVE-2014-8538 The Hijab Modern (aka com.Aisyaidea.HijabModern) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in… Hijab Modern Mitigation only Fix from $1,6002014-10-29