Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 7.8 CVE-2017-13091 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13092 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13093 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13094 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13095 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13096 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-13097 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rig… Mitigation only Fix from $1,9502018-07-13 HIGH 7.5 CVE-2013-3017 IBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat crypt… Tivoli Application Dependency Discovery Manager 7.2.1.5+ Fix from $1,9502018-07-09 HIGH 7.5 CVE-2016-10725 In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because… Bitcoin Core 0.13.0+ Fix from $1,9502018-07-05 MEDIUM 5.3 CVE-2011-4190 The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. Thi… Suse Linux Enterprise Desktop Mitigation only Fix from $1,6002018-06-08 HIGH 7.4 CVE-2016-1000344 In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and … Bc Java after 1.55 Fix from $1,9502018-06-04 HIGH 7.4 CVE-2016-1000352 In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and … Bc Java after 1.55 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10695 The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, … Npm Test Sqlite3 Trunk after 4.0.1 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10696 windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTP, which l… Windows Latestchromedriver Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10697 react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources o… React Native Baidu Voice Synthesizer Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10676 rs-brightcove is a wrapper around brightcove's web api rs-brightcove downloads source file resources over HTTP, which leaves it vulnerable to MITM at… Rs Brightcove after 0.0.2 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10677 google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-latest do… Google Closure Tools Latest after 0.1.1 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10678 serc.js is a Selenium RC process wrapper serc.js downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible… Serc.js Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10683 arcanist downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swappi… Arcanist Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10684 healthcenter - IBM Monitoring and Diagnostic Tools health Center agent healthcenter downloads binary resources over HTTP, which leaves it vulnerable … Healthcenter Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10685 pk-app-wonderbox is an integration with wonderbox pk-app-wonderbox downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. … Pk App Wonderbox Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10686 fis-sass-all is another libsass wrapper for node. fis-sass-all downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It m… Fis Sass All Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10687 windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources over HTTP, w… Windows Selenium Chromedriver Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10688 Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulnerable t… Haxe after 3.4.7 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10689 The windows-iedriver module downloads fixed version of iedriverserver.exe windows-iedriver downloads binary resources over HTTP, which leaves it vuln… Windows Iedriver Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10690 openframe-ascii-image module is an openframe plugin which adds support for ascii images via fim. openframe-ascii-image downloads resources over HTTP,… Openframe Ascii Image Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10691 windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves it vulner… Windows Seleniumjar Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10692 haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be po… Haxeshim after 0.12.4 Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10693 pm2-kafka is a PM2 module that installs and runs a kafka server pm2-kafka downloads binary resources over HTTP, which leaves it vulnerable to MITM at… Pm2 Kafka Mitigation only Fix from $1,9502018-06-04 HIGH 8.1 CVE-2016-10694 alto-saxophone is a module to install and launch Chromedriver for Mac, Linux or Windows. alto-saxophone versions below 2.25.1 download binary resourc… Alto Saxophone 2.25.1+ Fix from $1,9502018-06-04