Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Chrome MEDIUM 5.3
CVE-2017-15423

Inappropriate implementation in BoringSSL SPAKE2 in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to leak the low-order bits of SHA51…

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Android HIGH 7.8
CVE-2015-9003

In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.

Patch available
Fix from $1,950 2017-05-16
Chrome MEDIUM 6.5
CVE-2016-1618

Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi…

Fix: after 47.0.2526.106
Fix from $1,600 2016-01-25
Chrome HIGH 7.5
CVE-2014-1568EPSS 16%

Mozilla Network Security Services (NSS) before 3.16.2.1, 3.16.x before 3.16.5, and 3.17.x before 3.17.1, as used in Mozilla Firefox before 32.0.3, Mo…

Fix: after 37.0.2062.120
Fix from $1,950 2014-09-25
Chrome MEDIUM 6.4
CVE-2013-6659

The SSLClientSocketNSS::Core::OwnAuthCertHandler function in net/socket/ssl_client_socket_nss.cc in Google Chrome before 33.0.1750.117 does not preve…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Chrome MEDIUM 5.0
CVE-2012-2898

Google Chrome before 21.0.1180.82 on iOS on iPad devices allows remote attackers to spoof the Omnibox URL via vectors involving SSL error messages, a…

Fix: after 21.0.1180.81
Fix from $1,600 2014-01-05
Android HIGH 9.3
CVE-2013-4787EPSS 59%

Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitra…

Mitigation only
Fix from $1,950 2013-07-09
Cityhash MEDIUM 5.0
CVE-2012-6051

Google CityHash computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent …

Mitigation only
Fix from $1,600 2012-11-28
Android HIGH 10.0
CVE-2011-2344

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which al…

Mitigation only
Fix from $1,950 2011-07-08
Chrome HIGH 7.5
CVE-2009-3456

Google Chrome, possibly 3.0.195.21 and earlier, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of…

Fix: after 3.0.195.21
Fix from $1,950 2009-09-29
Chrome MEDIUM 6.4
CVE-2009-2973

Google Chrome before 2.0.172.43 does not prevent SSL connections to a site with an X.509 certificate signed with the (1) MD2 or (2) MD4 algorithm, wh…

Fix: after 2.0.172.37
Fix from $1,600 2009-08-27