Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 7.5 CVE-2009-2951 Phenotype CMS before 2.9 does not use a random salt value for password encryption, which makes it easier for context-dependent attackers to determine… Phenotype Cms after 2.8 Fix from $1,9502009-08-24 HIGH 10.0 CVE-2008-7023 Aruba Mobility Controller running ArubaOS 3.3.1.16, and possibly other versions, installs the same default X.509 certificate for all installations, w… Aruba Mobility Controller Mitigation only Fix from $1,9502009-08-21 HIGH 10.0 CVE-2008-6993 Siemens Gigaset WLAN Camera 1.27 has an insecure default password, which allows remote attackers to conduct unauthorized activities. NOTE: the proven… Gigaset Wlan Camera Mitigation only Fix from $1,9502009-08-19 HIGH 7.5 CVE-2009-2417 lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject'… Libcurl Patch available Fix from $1,9502009-08-14 HIGH 7.5 CVE-2009-2730 libgnutls in GnuTLS before 2.8.2 does not properly handle a '\0' character in a domain name in the subject's (1) Common Name (CN) or (2) Subject Alte… Gnutls after 2.8.1 Fix from $1,9502009-08-12 MEDIUM 6.4 CVE-2009-2666 socket.c in fetchmail before 6.3.11 does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 ce… Fetchmail after 6.3.10 Fix from $1,6002009-08-07 MEDIUM 6.5 CVE-2008-6909 Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not sign all required data in requests, which has unspecified impact,… Services Patch available Fix from $1,6002009-08-06 HIGH 7.5 CVE-2008-6910 Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts for signed requests, which allows remote attackers t… Services Patch available Fix from $1,9502009-08-06 HIGH 7.5 CVE-2008-6908 Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, uses an insecure hash when signing requests, which allows remote attackers… Services Patch available Fix from $1,9502009-08-06 MEDIUM 5.0 CVE-2009-2661 The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with cr… Strongswan Patch available Fix from $1,6002009-08-04 MEDIUM 5.0 CVE-2009-2319 The default configuration of the Wi-Fi component on the Axesstel MV 410R does not use encryption, which makes it easier for remote attackers to obtai… Mv 410r Mitigation only Fix from $1,6002009-07-05 HIGH 9.3 CVE-2009-2061 Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to ex… Firefox after 3.0.9 Fix from $1,9502009-06-15 MEDIUM 5.0 CVE-2009-1696 WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 uses predictable random numbers in Jav… Safari after 4.0_beta Fix from $1,6002009-06-10 HIGH 10.0 CVE-2008-6824 The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it easier fo… Wl54ap2 Patch available Fix from $1,9502009-06-04 HIGH 10.0 CVE-2009-1472 The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded A… Kh1516i Ip Kvm Switch Mitigation only Fix from $1,9502009-05-27 HIGH 10.0 CVE-2009-1473 The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.… Kh1516i Ip Kvm Switch Mitigation only Fix from $1,9502009-05-27 HIGH 7.6 CVE-2009-1474 The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes … Kh1516i Ip Kvm Switch Mitigation only Fix from $1,9502009-05-27 HIGH 10.0 CVE-2009-1477 The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 powe… Kh1516i Ip Kvm Switch Mitigation only Fix from $1,9502009-05-27 HIGH 7.8 CVE-2008-6797 The server in Mitel NuPoint Messenger R11 and R3 sends usernames and passwords in cleartext to Exchange servers, which allows remote attackers to obt… Mitel Nupoint Messenger Mitigation only Fix from $1,9502009-05-07 MEDIUM 5.0 CVE-2008-6792 system-tools-backends before 2.6.0-1ubuntu1.1 in Ubuntu 8.10, as used by "Users and Groups" in GNOME System Tools, hashes account passwords with 3DES… Linux Mitigation only Fix from $1,6002009-05-07 HIGH 7.8 CVE-2009-1560 The Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 stores passwords and wireless-network keys in cleartext in (1) pas… Wvc54gc No fix yet Fix from $1,9502009-05-06 HIGH 7.5 CVE-2009-1416 lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might… Gnutls Patch available Fix from $1,9502009-04-30 MEDIUM 5.0 CVE-2009-1417 gnutls-cli in GnuTLS before 2.6.6 does not verify the activation and expiration times of X.509 certificates, which allows remote attackers to success… Gnutls after 2.6.5 Fix from $1,6002009-04-30 MEDIUM 6.8 CVE-2009-1283 glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privile… Glfusion after 1.1.2 Fix from $1,6002009-04-09 HIGH 10.0 CVE-2009-1174 The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "securi… Websphere Application Server Patch available Fix from $1,9502009-03-31 MEDIUM 5.0 CVE-2009-1074 Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to … Java System Identity Manager Patch available Fix from $1,6002009-03-25 HIGH 7.8 CVE-2009-0742 The username command in Cisco ACE Application Control Engine Module for Catalyst 6500 Switches and 7600 Routers and Cisco ACE 4710 Application Contro… Application Control Engine Module Patch available Fix from $1,9502009-02-26 MEDIUM 5.0 CVE-2008-6193 Sam Crew MyBlog stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. Myblog No fix yet Fix from $1,6002009-02-19 MEDIUM 5.0 CVE-2009-0547 Evolution 2.22.3.1 checks S/MIME signatures against a copy of the e-mail text within a signed-data blob, not the copy of the e-mail text displayed to… Evolution Mitigation only Fix from $1,6002009-02-12 MEDIUM 5.0 CVE-2009-0047 Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass val… Gale after 0.99 Fix from $1,6002009-01-07