Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
CRITICAL 9.8 CVE-2004-2761EPSS 10% The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as de… Md5 Patch available Fix from $2,3002009-01-05 HIGH 7.5 CVE-2008-5659 The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for… Classpath after 0.97.2 Fix from $1,9502008-12-17 HIGH 7.8 CVE-2008-5410 The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which … Solaris Patch available Fix from $1,9502008-12-10 MEDIUM 5.0 CVE-2008-5411 IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain … Websphere Application Server after 7.0 Fix from $1,6002008-12-10 HIGH 7.5 CVE-2008-5331 Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute… Acrobat Mitigation only Fix from $1,9502008-12-05 MEDIUM 5.0 CVE-2008-3057 Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes i… Oempro No fix yet Fix from $1,6002008-12-03 HIGH 7.5 CVE-2008-4227 Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 changes the encryption level of PPTP VPN connections to a lower level th… Iphone Os Mitigation only Fix from $1,9502008-11-25 MEDIUM 6.8 CVE-2008-5230 The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi… iOS No fix yet Fix from $1,6002008-11-25 HIGH 10.0 CVE-2008-5100EPSS 8% The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname o… .net Framework No fix yet Fix from $1,9502008-11-17 MEDIUM 5.0 CVE-2008-4368 The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE… Mac Os X Mitigation only Fix from $1,6002008-10-01 MEDIUM 5.0 CVE-2008-3663 Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests a… Squirrelmail Mitigation only Fix from $1,6002008-09-24 MEDIUM 5.0 CVE-2008-3102 Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the coo… Mantisbt Mitigation only Fix from $1,6002008-09-24 MEDIUM 5.0 CVE-2008-3662 Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, which can cause the cookie to be… Gallery after 2.2.5 Fix from $1,6002008-09-18 MEDIUM 5.0 CVE-2008-3671 Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain se… True Image Echo Server No fix yet Fix from $1,6002008-08-13 MEDIUM 6.8 CVE-2008-3532 The NSS plugin in libpurple in Pidgin 2.4.3 does not verify SSL certificates, which makes it easier for remote attackers to trick a user into accepti… Pidgin Patch available Fix from $1,6002008-08-08 MEDIUM 5.0 CVE-2008-3288 The Server Authentication Module in EMC Dantz Retrospect Backup Server 7.5.508 uses a "weak hash algorithm," which makes it easier for context-depend… Dantz Retrospect Backup Server Patch available Fix from $1,6002008-07-24 MEDIUM 5.0 CVE-2008-3236 Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allo… Websphere Application Server Mitigation only Fix from $1,6002008-07-21 MEDIUM 6.4 CVE-2008-2780 The Anubis (aka Anubis+Ripe160) plugin before 1.3 for encrypt stores the unencrypted file's size in cleartext in the header of the encrypted file, wh… Anubis Plugin after 1.2 Fix from $1,6002008-06-19 MEDIUM 5.0 CVE-2008-2558 CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff… Cre Loaded after 6.2.13.1 Fix from $1,6002008-06-05 MEDIUM 5.0 CVE-2008-2285 The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier fo… Linux Mitigation only Fix from $1,6002008-05-18 MEDIUM 5.0 CVE-2008-2299 Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and… Presentation Server after 4.5 Fix from $1,6002008-05-18 HIGH 7.5 CVE-2008-1886EPSS 7% The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for a KeyCode that blocks unauth… Download Client No fix yet Fix from $1,9502008-04-18 MEDIUM 5.0 CVE-2008-1772 iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sensitive information. Socialware No fix yet Fix from $1,6002008-04-14 MEDIUM 5.0 CVE-2008-1711 Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attac… Advanced Web Photo Gallery No fix yet Fix from $1,6002008-04-09 HIGH 7.5 CVE-2008-1527 ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication … Prestige 660 Mitigation only Fix from $1,9502008-03-26 MEDIUM 5.0 CVE-2008-0759 ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an … Extremez Ip File Server after 5.1.2 Fix from $1,6002008-02-13 MEDIUM 6.4 CVE-2007-6635 FAQMasterFlexPlus, possibly 1.5 or 1.52, stores the admin password in cleartext in a database, which might allow context-dependent attackers to obtai… Faqmasterflexplus No fix yet Fix from $1,6002008-01-04 HIGH 10.0 CVE-2007-6521EPSS 5% Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates. Opera Browser after 9.24 Fix from $1,9502007-12-24 HIGH 9.3 CVE-2007-5863EPSS 23% Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the clie… Mac Os X Mitigation only Fix from $1,9502007-12-19 MEDIUM 6.4 CVE-2007-5502 The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data… Fips Object Module Patch available Fix from $1,6002007-12-01