Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 9.7 CVE-2014-2046 cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obt… Pipa C211 Web Interface No fix yet Fix from $1,9502014-05-14 MEDIUM 5.0 CVE-2013-0173 Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attac… Foreman after 1.0 Fix from $1,6002014-05-08 MEDIUM 6.9 CVE-2014-0646 The runtime WS component in the server in EMC RSA Access Manager 6.1.3 before 6.1.3.39, 6.1.4 before 6.1.4.22, 6.2.0 before 6.2.0.11, and 6.2.1 befor… Rsa Access Manager Mitigation only Fix from $1,6002014-05-01 MEDIUM 5.0 CVE-2014-0786 Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverag… Integraxor after 4.1.4390 Fix from $1,6002014-05-01 MEDIUM 5.0 CVE-2013-6445 Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier… Enterprise Mrg Mitigation only Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2013-7372 The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.… Harmony after 6.0 Fix from $1,6002014-04-29 MEDIUM 6.4 CVE-2011-3152 DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x b… Update Manager after 1 Fix from $1,6002014-04-27 MEDIUM 6.4 CVE-2014-2992 The Misli.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers … Misli.com App Mitigation only Fix from $1,6002014-04-26 MEDIUM 6.4 CVE-2014-2993 The Birebin.com application for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof server… Birebin.com App Mitigation only Fix from $1,6002014-04-26 MEDIUM 6.4 CVE-2014-0350 The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof … Poco C\+\+ Libraries after 1.4.6 Fix from $1,6002014-04-26 MEDIUM 5.8 CVE-2014-2900 wolfSSL CyaSSL before 2.9.4 does not properly validate X.509 certificates with unknown critical extensions, which allows man-in-the-middle attackers … Cyassl after 2.9.0 Fix from $1,6002014-04-22 MEDIUM 5.0 CVE-2013-6371 The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data,… Fedora 0.12-20140410+ Fix from $1,6002014-04-22 MEDIUM 6.8 CVE-2014-0036 The rbovirt gem before 0.0.24 for Ruby uses the rest-client gem with SSL verification disabled, which allows remote attackers to conduct man-in-the-m… Rbovirt after 0.0.23 Fix from $1,6002014-04-17 MEDIUM 5.8 CVE-2014-0139 cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'… Curl Mitigation only Fix from $1,6002014-04-15 MEDIUM 5.8 CVE-2014-0636 EMC RSA BSAFE Micro Edition Suite (MES) 3.2.x before 3.2.6 and 4.0.x before 4.0.5 does not properly validate X.509 certificate chains, which allows m… Bsafe Micro Edition Suite Mitigation only Fix from $1,6002014-04-11 MEDIUM 5.8 CVE-2014-1210 VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attac… Vsphere Client Mitigation only Fix from $1,6002014-04-11 MEDIUM 5.0 CVE-2013-5444 The server in IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows remote attackers to read encr… Cognos Express Mitigation only Fix from $1,6002014-03-25 MEDIUM 5.0 CVE-2013-5445 IBM Cognos Express 9.0 before IFIX 2, 9.5 before IFIX 2, 10.1 before IFIX 2, and 10.2.1 before FP1 allows local users to obtain sensitive cleartext i… Cognos Express Mitigation only Fix from $1,6002014-03-25 HIGH 8.3 CVE-2014-2250 The random-number generator on Siemens SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 does not have sufficient entropy, which makes it easi… Simatic S7 Cpu 1200 Firmware after 3.0.2 Fix from $1,9502014-03-24 MEDIUM 5.0 CVE-2013-6401 Jansson, possibly 2.4 and earlier, does not restrict the ability to trigger hash collisions predictably, which allows context-dependent attackers to … Jansson after 2.4 Fix from $1,6002014-03-21 MEDIUM 5.8 CVE-2014-1976 The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers … Demaecan after 2.1.0 Fix from $1,6002014-03-18 HIGH 8.5 CVE-2013-1398 The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows rem… Puppet Enterprise after 2.7.0 Fix from $1,9502014-03-14 MEDIUM 5.0 CVE-2014-2319 The Encrypt Files feature in ConeXware PowerArchiver before 14.02.05 uses legacy ZIP encryption even if the AES 256-bit selection is chosen, which ma… Powerarchiver after 14.02.03 Fix from $1,6002014-03-14 MEDIUM 5.2 CVE-2014-0102 The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings… Linux Kernel after 3.13.6 Fix from $1,6002014-03-11 MEDIUM 5.8 CVE-2014-0092EPSS 30% lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from … Gnutls after 3.2.11 Fix from $1,6002014-03-07 MEDIUM 5.0 CVE-2013-5468 IBM Algo One, as used in MetaData Management Tools in UDS 4.7.0 through 5.0.0, ACSWeb in Algo Security Access Control Management 4.7.0 through 4.9.0,… Algo One Mitigation only Fix from $1,6002014-03-05 MEDIUM 5.8 CVE-2014-1967 The Denny's application before 2.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spo… Denny\'s after 2.0.0 Fix from $1,6002014-02-27 MEDIUM 6.2 CVE-2014-0741 The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified… Unified Communications Manager after 10.0 Fix from $1,6002014-02-27 HIGH 10.0 CVE-2013-3712 SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vector… Studio Extension For System Z No fix yet Fix from $1,9502014-02-26 MEDIUM 6.4 CVE-2013-6659 The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not preve… Chrome after 33.0.1750.116 Fix from $1,6002014-02-24