Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
MEDIUM 5.4 CVE-2014-5527 The Tapjoy library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obt… Tapjoy Library Mitigation only Fix from $1,6002014-09-09 MEDIUM 5.4 CVE-2014-5528 The Appsflyer library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and … Appsflyer Mitigation only Fix from $1,6002014-09-09 MEDIUM 5.4 CVE-2014-5529 The Gameloft library for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and o… Gameloft Library Mitigation only Fix from $1,6002014-09-09 MEDIUM 5.4 CVE-2014-2379 Sensys Networks VSN240-F and VSN240-T sensors VDS before 2.10.1 and TrafficDOT before 2.10.3 do not use encryption, which allows remote attackers to … Trafficdot after 2.10.2 Fix from $1,6002014-09-05 MEDIUM 5.8 CVE-2014-3908 The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack… Kindle after 4.4.4 Fix from $1,6002014-08-30 MEDIUM 5.0 CVE-2014-3436 Symantec Encryption Desktop 10.3.x before 10.3.2 MP3, and Symantec PGP Desktop 10.0.x through 10.2.x, allows remote attackers to cause a denial of se… Pgp Desktop Mitigation only Fix from $1,6002014-08-22 MEDIUM 5.8 CVE-2014-3902 The CyberAgent Ameba application 3.x and 4.x before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mi… Ameba after 4.4.0 Fix from $1,6002014-08-15 MEDIUM 5.8 CVE-2014-3302 user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allow… Webex Meetings Server after 1.5 Fix from $1,6002014-08-01 MEDIUM 5.0 CVE-2014-4911 The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of servi… Debian Linux after 1.2.10 Fix from $1,6002014-07-22 MEDIUM 5.0 CVE-2014-3503EPSS 6% Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via… Syncope No fix yet Fix from $1,6002014-07-11 MEDIUM 5.0 CVE-2014-0860 The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), an… Integrated Management Module Firmware after 3.65 Fix from $1,6002014-07-07 MEDIUM 5.8 CVE-2014-2001 The East Japan Railway Company JR East Japan application before 1.2.0 for Android does not verify X.509 certificates from SSL servers, which allows m… Jr East Japan after 1.0 Fix from $1,6002014-06-19 MEDIUM 5.0 CVE-2014-4040 snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning abo… Powerpc Utils Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.0 CVE-2014-4191 The TLS implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) sends a long series of random bytes during use of the Dual_EC_DRBG algor… Bsafe Share Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.0 CVE-2014-4192 The Dual_EC_DRBG implementation in EMC RSA BSAFE-C Toolkits (aka Share for C and C++) processes certain requests for output bytes by considering only… Bsafe Share Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.0 CVE-2014-4193 The TLS implementation in EMC RSA BSAFE-Java Toolkits (aka Share for Java) supports the Extended Random extension during use of the Dual_EC_DRBG algo… Bsafe Share Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.8 CVE-2013-6078 The default configuration of EMC RSA BSAFE Toolkits and RSA Data Protection Manager (DPM) 20130918 uses the Dual Elliptic Curve Deterministic Random … Rsa Bsafe Toolkits Mitigation only Fix from $1,6002014-06-17 MEDIUM 5.0 CVE-2014-3812 The Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS before 7.4r5 and 8.x before 8.0r1 and Junos Pulse Access Control Service … Ive Os Mitigation only Fix from $1,6002014-06-13 MEDIUM 5.8 CVE-2012-5583 phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X… Phpcas after 1.3.1 Fix from $1,6002014-06-06 MEDIUM 5.0 CVE-2013-1941 The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation o… Owncloud after 4.0.13 Fix from $1,6002014-06-04 MEDIUM 5.0 CVE-2013-2125 OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by kee… Opensmtpd after 5.3.1 Fix from $1,6002014-05-27 MEDIUM 5.8 CVE-2012-5662 x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t… X3270 after 3.3.12 Fix from $1,6002014-05-27 MEDIUM 5.8 CVE-2014-0878 The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh… Java Sdk Mitigation only Fix from $1,6002014-05-26 MEDIUM 5.0 CVE-2013-2758EPSS 6% Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se… Cloudstack Patch available Fix from $1,6002014-05-23 MEDIUM 5.8 CVE-2013-4347 The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, w… Python Oauth2 Patch available Fix from $1,6002014-05-20 MEDIUM 6.8 CVE-2013-7385 LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php,… Livezilla after 5.1.2.1 Fix from $1,6002014-05-19 MEDIUM 5.0 CVE-2013-6805 OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffi… Exceed Ondemand Mitigation only Fix from $1,6002014-05-19 MEDIUM 6.8 CVE-2013-6807 The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certi… Exceed Ondemand Mitigation only Fix from $1,6002014-05-19 MEDIUM 6.4 CVE-2013-6994 OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing… Exceed Ondemand Mitigation only Fix from $1,6002014-05-19 MEDIUM 5.8 CVE-2014-3750 The Bilyoner application before 2.3.1 for Android and before 4.6.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-t… Bilyoner after 4.6 Fix from $1,6002014-05-16