Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
HIGH 7.1 CVE-2007-5792 The Vonage Motorola Phone Adapter VT 2142-VD does not encrypt RTP packets, which might allow remote attackers to eavesdrop by sniffing the network an… Motorola Phone Adapter Vt2142 Vd Mitigation only Fix from $1,9502007-11-01 MEDIUM 5.0 CVE-2007-5768 The Globe7 soft phone client 7.3 sends username and password information in cleartext, which allows remote attackers to obtain sensitive information … Globe7 Mitigation only Fix from $1,6002007-10-31 MEDIUM 6.8 CVE-2007-5195 Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto… Suse Linux Patch available Fix from $1,6002007-10-14 HIGH 7.5 CVE-2007-5196 Unspecified vulnerability in the SSL implementation in Groupwise client system in the novell-groupwise-client package in SUSE Linux Enterprise Deskto… Suse Linux Mitigation only Fix from $1,9502007-10-14 MEDIUM 5.0 CVE-2007-4960 Argument injection vulnerability in the Linden Lab Second Life secondlife:// protocol handler, as used in Internet Explorer and possibly Firefox, all… Second Life Mitigation only Fix from $1,6002007-09-18 HIGH 9.3 CVE-2007-4750 Unspecified vulnerability in RemoteDocs R-Viewer before 1.6.3768 allows user-assisted remote attackers to execute arbitrary code via a crafted RDZ ar… Remotedocs R Viewer after 1.6.2836 Fix from $1,9502007-09-18 HIGH 9.3 CVE-2007-4926 The AXIS 207W camera uses a base64-encoded cleartext username and password for authentication, which allows remote attackers to obtain sensitive info… 207w Camera Mitigation only Fix from $1,9502007-09-18 MEDIUM 6.8 CVE-2007-4613 SSL libraries in BEA WebLogic Server 6.1 Gold through SP7, 7.0 Gold through SP7, and 8.1 Gold through SP5 might allow remote attackers to obtain plai… Weblogic Server Patch available Fix from $1,6002007-08-31 MEDIUM 6.8 CVE-2007-4311 The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few byte… Linux Kernel after 2.4.34 Fix from $1,6002007-08-13 MEDIUM 5.4 CVE-2007-3805 The IKE implementation in Clavister CorePlus before 8.80.03, and 8.80.00, does not properly validate certificates during IKE negotiation, which allow… Clavister Coreplus after 8.80.03 Fix from $1,6002007-07-16 HIGH 10.0 CVE-2006-5982 SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to obtain pa… Seleniumserver Ftp Server Mitigation only Fix from $1,9502006-11-20 HIGH 10.0 CVE-2006-0270 Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impact and att… Database Server Mitigation only Fix from $1,9502006-01-18 MEDIUM 5.0 CVE-2003-1344 Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords, and other sensitive informati… Virus Control System No fix yet Fix from $1,6002003-12-31 HIGH 7.5 CVE-2003-1389 RTS CryptoBuddy 1.2 and earlier truncates long passphrases without warning the user, which may make it easier to conduct certain brute force guessing… Cryptobuddy Mitigation only Fix from $1,9502003-12-31 HIGH 7.5 CVE-2003-1390 RTS CryptoBuddy 1.2 and earlier stores bytes 53 through 55 of a 55-byte passphrase in plaintext, which makes it easier for local users to guess the p… Cryptobuddy Mitigation only Fix from $1,9502003-12-31 HIGH 7.5 CVE-2003-1391 RTS CryptoBuddy 1.0 and 1.2 uses a weak encryption algorithm for the passphrase and generates predictable keys, which makes it easier for attackers t… Cryptobuddy Mitigation only Fix from $1,9502003-12-31 MEDIUM 6.6 CVE-2003-1392 CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decry… Cryptobuddy Mitigation only Fix from $1,6002003-12-31 MEDIUM 6.4 CVE-2003-1483 FlashFXP 1.4 uses a weak encryption algorithm for user passwords, which allows attackers to decrypt the passwords and gain access. Flashfxp No fix yet Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-0512 Cisco IOS 12.2 and earlier generates a "% Login invalid" message instead of prompting for a password when an invalid username is provided, which allo… iOS Mitigation only Fix from $1,6002003-08-27 HIGH 7.8 CVE-2002-2303 3D3.Com ShopFactory 5.8 uses client-side encryption and decryption for sensitive price data, which allows remote attackers to modify shopping cart pr… Shopfactory Mitigation only Fix from $1,9502002-12-31 MEDIUM 5.0 CVE-2002-2326 The default configuration of Mail.app in Mac OS X 10.0 through 10.0.4 and 10.1 through 10.1.5 sends iDisk authentication credentials in cleartext whe… Mac Os X Mitigation only Fix from $1,6002002-12-31 HIGH 7.8 CVE-2002-2379EPSS 6% Cisco AS5350 IOS 12.2(11)T with access control lists (ACLs) applied and possibly with ssh running allows remote attackers to cause a denial of servic… As5350 No fix yet Fix from $1,9502002-12-31 HIGH 7.5 CVE-2001-1463 The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication… Serv U File Server No fix yet Fix from $1,9502001-11-19 HIGH 7.5 CVE-2001-1473EPSS 6% The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a… Ssh Mitigation only Fix from $1,9502001-01-18 HIGH 7.5 CVE-2000-0589 SawMill 5.0.21 uses weak encryption to store passwords, which allows attackers to easily decrypt the password and modify the SawMill configuration. Sawmill Patch available Fix from $1,9502000-06-26