Перейти к содержимому
Noroxi

CWE-320 · 88 записей

Key Management Errors

CVE этого класса

88 записей

  • CVE-2015-0936
    62На этой неделе

    Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtai

    КритическаяCVSS 9,8Готовый эксплойтEPSS 78 %

    ceragon · fibeair ip-10 firmware1 июн. 2017 г.

  • CVE-2018-0732
    45В плане

    Client DoS due to large DH parameter

    ВысокаяCVSS 7,5Эксплойта нетEPSS 49 %

    openssl · openssl12 июн. 2018 г.

  • CVE-2018-0124
    41В плане

    A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protection

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    cisco · unified communications domain manager21 февр. 2018 г.

  • CVE-2016-10467
    39Наблюдать

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, S

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qualcomm · sd 210 firmware18 апр. 2018 г.

  • CVE-2016-10421
    39Наблюдать

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    qualcomm · mdm9206 firmware18 апр. 2018 г.

  • CVE-2015-4166
    39Наблюдать

    Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vecto

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudera · key trustee server23 мар. 2017 г.

  • CVE-2015-8542
    36Наблюдать

    An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    open-xchange · ox guard15 дек. 2016 г.

  • CVE-2019-5672
    36Наблюдать

    NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the S

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    nvidia · jetson tx111 апр. 2019 г.

  • CVE-2015-0839
    34Наблюдать

    The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by

    ВысокаяCVSS 8,1Эксплойта нетEPSS 6 %

    hp · linux imaging and printing2 авг. 2017 г.

  • CVE-2026-56254
    33Наблюдать

    capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution

    ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %

    capacitor-updater · capacitor-updater10 июл. 2026 г.

  • CVE-2019-9894
    31Наблюдать

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    putty · putty21 мар. 2019 г.

  • CVE-2018-9234
    31Наблюдать

    GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    gnupg · gnupg3 апр. 2018 г.

  • CVE-2015-0153
    31Наблюдать

    D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    dlink · dir-815 firmware12 апр. 2018 г.

  • CVE-2016-6886
    31Наблюдать

    The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    matrixssl · matrixssl13 янв. 2017 г.

  • CVE-2016-2880
    31Наблюдать

    IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    ibm · qradar security information and event manager1 мар. 2017 г.

  • CVE-2013-2233
    30Наблюдать

    Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.

    ВысокаяCVSS 7,4Эксплойта нетEPSS 2 %

    redhat · ansible4 мая 2018 г.

  • CVE-2015-7503
    30Наблюдать

    Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    zend · zend framework10 окт. 2017 г.

  • CVE-2015-1316
    30Наблюдать

    Juju Joyent provider uploads user's private ssh key by default

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    canonical · juju22 апр. 2019 г.

  • CVE-2021-26322
    30Наблюдать

    Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    amd · epyc 7601 firmware16 нояб. 2021 г.

  • CVE-2017-13887
    30Наблюдать

    In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    apple · mac os x11 янв. 2019 г.

  • CVE-2016-6879
    30Наблюдать

    The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    botan project · botan10 апр. 2017 г.

  • CVE-2019-12621
    29Наблюдать

    Cisco HyperFlex Static SSL Key Vulnerability

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    cisco · hyperflex hx220c m5 firmware21 авг. 2019 г.

  • CVE-2024-36391
    29Наблюдать

    MileSight DeviceHub - CWE-320: Key Management Errors

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    milesight · devicehub2 июн. 2024 г.

  • CVE-2014-2361
    28Наблюдать

    OleumTech WIO Family Key Management Errors

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    oleumtech · sensor wireless i\/o module24 июл. 2014 г.

  • CVE-2023-21626
    28Наблюдать

    Improper Authentication in HLOS.

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    qualcomm · apq8009 firmware8 авг. 2023 г.

Все классы уязвимостей