Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 7.5 CVE-2012-0381 The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S,… iOS 3.2.2sg / 3.4.1s+ Fix from $1,9502012-03-29 HIGH 7.8 CVE-2012-0386 The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows … iOS Mitigation only Fix from $1,9502012-03-29 MEDIUM 5.0 CVE-2012-1573 gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows… Gnutls after 2.12.16 Fix from $1,6002012-03-26 HIGH 7.5 CVE-2012-0039 GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predic… Glib after 2.31.8 Fix from $1,9502012-01-14 MEDIUM 5.3 CVE-2011-4461 Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which al… Sun Storage Common Array Manager after 8.1.0 Fix from $1,6002011-12-30 MEDIUM 5.0 CVE-2011-5036 Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger has… Rack after 1.1.0 Fix from $1,6002011-12-30 MEDIUM 5.0 CVE-2011-4758 Parallels Plesk Small Business Panel 10.2.0 receives cleartext password input over HTTP, which allows remote attackers to obtain sensitive informatio… Parallels Plesk Small Business Panel Mitigation only Fix from $1,6002011-12-16 MEDIUM 5.0 CVE-2011-4746 The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not disable the SSL 2.0 protocol, which makes it easier for remote attack… Parallels Plesk Panel Mitigation only Fix from $1,6002011-12-16 MEDIUM 5.0 CVE-2011-4747 The billing system for Parallels Plesk Panel 10.3.1_build1013110726.09 does not prevent the use of weak ciphers for SSL sessions, which makes it easi… Parallels Plesk Panel Mitigation only Fix from $1,6002011-12-16 MEDIUM 5.0 CVE-2011-4736 The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 receives cleartext password input over HTTP, which allows remote attackers to obt… Parallels Plesk Panel Mitigation only Fix from $1,6002011-12-16 HIGH 10.0 CVE-2011-4684EPSS 6% Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases." Opera Browser after 11.60 Fix from $1,9502011-12-07 MEDIUM 5.0 CVE-2011-4321 The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the p… Joomla\! Mitigation only Fix from $1,6002011-11-23 HIGH 7.5 CVE-2011-4507EPSS 6% The D-Link DIR-685 router, when certain WPA and WPA2 configurations are used, does not maintain an encrypted wireless network during transfer of a la… Dir 685 Mitigation only Fix from $1,9502011-11-22 MEDIUM 5.0 CVE-2011-4046 The Dell KACE K2000 System Deployment Appliance stores the recovery account password in cleartext within a PHP script, which allows context-dependent… Kace K2000 Systems Deployment Appliance Mitigation only Fix from $1,6002011-11-12 MEDIUM 5.0 CVE-2011-4432 www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password ha… Centreon after 2.3.1 Fix from $1,6002011-11-10 MEDIUM 5.8 CVE-2011-3599 The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for … Crypt Dsa after 1.17 Fix from $1,6002011-10-10 MEDIUM 5.0 CVE-2011-1509 The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in … Servicedesk Plus after 8012 Fix from $1,6002011-09-20 MEDIUM 5.0 CVE-2011-2736 RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obt… Envision Mitigation only Fix from $1,6002011-08-25 MEDIUM 5.0 CVE-2011-2483 crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-… PHP 1.1 / 5.3.7+ Fix from $1,6002011-08-25 MEDIUM 5.0 CVE-2011-3013 WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for… Data Synchronizer Mitigation only Fix from $1,6002011-08-09 MEDIUM 5.0 CVE-2011-2223 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 sends the Admin LDAP password in cleartext, which allows remote … Data Synchronizer Mitigation only Fix from $1,6002011-08-09 MEDIUM 5.0 CVE-2011-3009 Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of ra… Ruby after 1.8.6 Fix from $1,6002011-08-05 MEDIUM 5.0 CVE-2011-2686 Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of ra… Ruby after 1.8.7-334 Fix from $1,6002011-08-05 MEDIUM 5.0 CVE-2011-0214 CFNetwork in Apple Safari before 5.0.6 on Windows does not properly handle an untrusted attribute of a system root certificate, which allows remote w… Safari after 5.0.5 Fix from $1,6002011-07-21 HIGH 10.0 CVE-2011-2344 Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which al… Android Mitigation only Fix from $1,9502011-07-08 MEDIUM 5.0 CVE-2011-0207 The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows re… Mac Os X Patch available Fix from $1,6002011-06-24 HIGH 7.5 CVE-2011-1128 The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid logi… Smf after 1.1.12 Fix from $1,9502011-06-21 HIGH 7.8 CVE-2011-0766 The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses… Crypto after 2.0.4 Fix from $1,9502011-05-31 MEDIUM 5.0 CVE-2011-2151 The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser.aspx, and (5) Login.aspx com… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 5.8 CVE-2010-0217 Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions … Chat Server after 5.0 Fix from $1,6002011-05-20