Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Wicket HIGH 7.5
CVE-2014-7808

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism a…

Fix: 1.5.13 / 6.19.0+
Fix from $1,950 2017-09-15
HTTP Server HIGH 7.5
CVE-2016-0736EPSS 49%

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either C…

No fix yet
Fix from $1,950 2017-07-27
Mod Gnutls MEDIUM 5.0
CVE-2015-2091

The authentication hook (mgs_hook_authz) in mod-gnutls 0.5.10 and earlier does not validate client certificates when "GnuTLSClientVerify require" is …

Fix: after 0.5.1
Fix from $1,600 2015-03-13
Syncope MEDIUM 5.0
CVE-2014-3503EPSS 6%

Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via…

No fix yet
Fix from $1,600 2014-07-11
Cloudstack MEDIUM 5.0
CVE-2013-2758EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C uses a hash of a predictable se…

Patch available
Fix from $1,600 2014-05-23
Harmony MEDIUM 5.0
CVE-2013-7372

The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.…

Fix: after 6.0
Fix from $1,600 2014-04-29
Cxf MEDIUM 6.4
CVE-2012-5575EPSS 6%

Apache CXF 2.5.x before 2.5.10, 2.6.x before CXF 2.6.7, and 2.7.x before CXF 2.7.4 does not verify that a specified cryptographic algorithm is allowe…

Mitigation only
Fix from $1,600 2013-08-19
Hadoop HIGH 7.5
CVE-2012-3376

DataNodes in Apache Hadoop 2.0.0 alpha does not check the BlockTokens of clients when Kerberos is enabled and the DataNode has checked out the same B…

Mitigation only
Fix from $1,950 2012-07-12
Commons Compress MEDIUM 5.0
CVE-2012-2098EPSS 13%

Algorithmic complexity vulnerability in the sorting algorithms in bzip2 compressing stream (BZip2CompressorOutputStream) in Apache Commons Compress b…

Fix: 1.4.1+
Fix from $1,600 2012-06-29
Hadoop MEDIUM 6.5
CVE-2012-1574

The Kerberos/MapReduce security functionality in Apache Hadoop 0.20.203.0 through 0.20.205.0, 0.23.x before 0.23.2, and 1.0.x before 1.0.2, as used i…

Mitigation only
Fix from $1,600 2012-04-12
Myfaces MEDIUM 5.0
CVE-2010-2057

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M…

Patch available
Fix from $1,600 2010-10-20