CWE-310 · 2,325 records
Cryptographic Issues
CVEs in this class
2,325 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2014-8684Weaponized | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies andcodeigniter · codeigniter · CWE-310 | Critical9.8 | — | 71.7% | Sep 19, 2017 |
50Plan | CVE-2014-8686Weaponized | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption schcodeigniter · codeigniter · CWE-310 | Critical9.8 | — | 37.2% | Sep 19, 2017 |
49Plan | CVE-2012-1803Weaponized | RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the bsiemens · ruggedcom rugged operating system · CWE-310 | High8.5 | — | 49.0% | Apr 27, 2012 |
47Plan | CVE-2015-0204Proof of concept | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL seopenssl · openssl · CWE-310 | Medium4.3 | — | 98.7% | Jan 8, 2015 |
47Plan | CVE-2014-7228Weaponized | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!joomla · joomla\! · CWE-310 | High7.5 | — | 55.4% | Nov 3, 2014 |
45Plan | CVE-2009-4655Weaponized | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sesnovell · edirectory · CWE-310 | High7.5 | — | 50.5% | Feb 26, 2010 |
45Plan | CVE-2016-0736Proof of concept | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possiblyapache · http server · CWE-310 | High7.5 | — | 49.0% | Jul 27, 2017 |
44Plan | CVE-2015-4000Weaponized | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_Eopenssl · openssl · CWE-310 | Low3.7 | — | 99.9% | May 20, 2015 |
44Plan | CVE-2007-5863Weaponized | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack betweenapple · mac os x · CWE-310 | Critical9.3 | — | 23.0% | Dec 19, 2007 |
44Plan | CVE-2013-0137No exploit | The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device befdigital alert systems · dasdec eas · CWE-310 | Critical10.0 | — | 13.4% | Jun 30, 2013 |
43Plan | CVE-2014-3566Weaponized | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Low3.4 | — | 100.0% | Oct 14, 2014 |
43Plan | CVE-2014-7878No exploit | The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node imhp · helion cloud development platform · CWE-310 | Critical10.0 | — | 10.3% | Nov 13, 2014 |
43Plan | CVE-2008-5100No exploit | The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pmicrosoft · .net framework · CWE-310 | Critical10.0 | — | 8.4% | Nov 17, 2008 |
42Plan | CVE-2004-2761Proof of concept | The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacietf · md5 · CWE-310 | Critical9.8 | — | 9.9% | Jan 5, 2009 |
42Plan | CVE-2011-4684Proof of concept | Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corneopera · opera browser · CWE-310 | Critical10.0 | — | 5.7% | Dec 7, 2011 |
42Plan | CVE-2007-6521No exploit | Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.opera · opera browser · CWE-310 | Critical10.0 | — | 5.0% | Dec 24, 2007 |
41Plan | CVE-2013-4787Proof of concept | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to executgoogle · android · CWE-310 | Critical9.3 | — | 13.4% | Jul 9, 2013 |
41Plan | CVE-2006-0270No exploit | Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impacoracle · database server · CWE-310 | Critical10.0 | — | 4.9% | Jan 18, 2006 |
41Plan | CVE-2011-0935No exploit | The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers tocisco · ios · CWE-310 | Critical10.0 | — | 4.0% | Apr 14, 2011 |
41Plan | CVE-2013-6952No exploit | The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware ubelkin · wemo home automation firmware · CWE-310 | Critical10.0 | — | 3.8% | Feb 22, 2014 |
41Plan | CVE-2008-6824Proof of concept | The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it a-link · wl54ap2 · CWE-310 | Critical10.0 | — | 3.6% | Jun 4, 2009 |
41Plan | CVE-2009-1473No exploit | The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmaten · kh1516i ip kvm switch · CWE-310 | Critical10.0 | — | 3.2% | May 27, 2009 |
41Plan | CVE-2013-6838No exploit | An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usienghouseinteractive · ivr pro · CWE-310 | Critical10.0 | — | 2.8% | Jan 27, 2014 |
41Plan | CVE-2008-7252No exploit | libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and atphpmyadmin · phpmyadmin · CWE-310 | Critical10.0 | — | 2.7% | Jan 19, 2010 |
41Plan | CVE-2006-5982No exploit | SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to biba software · seleniumserver ftp server · CWE-310 | Critical10.0 | — | 2.7% | Nov 20, 2006 |
- CVE-2014-868461This week
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and
CriticalCVSS 9.8WeaponizedEPSS 72%codeigniter · codeigniterSep 19, 2017
- CVE-2014-868650Plan
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch
CriticalCVSS 9.8WeaponizedEPSS 37%codeigniter · codeigniterSep 19, 2017
- CVE-2012-180349Plan
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the b
HighCVSS 8.5WeaponizedEPSS 49%siemens · ruggedcom rugged operating systemApr 27, 2012
- CVE-2015-020447Plan
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL se
MediumCVSS 4.3Proof of conceptEPSS 99%openssl · opensslJan 8, 2015
- CVE-2014-722847Plan
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!
HighCVSS 7.5WeaponizedEPSS 55%joomla · joomla\!Nov 3, 2014
- CVE-2009-465545Plan
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack ses
HighCVSS 7.5WeaponizedEPSS 51%novell · edirectoryFeb 26, 2010
- CVE-2016-073645Plan
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly
HighCVSS 7.5Proof of conceptEPSS 49%apache · http serverJul 27, 2017
- CVE-2015-400044Plan
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E
LowCVSS 3.7WeaponizedEPSS 100%openssl · opensslMay 20, 2015
- CVE-2007-586344Plan
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between
CriticalCVSS 9.3WeaponizedEPSS 23%apple · mac os xDec 19, 2007
- CVE-2013-013744Plan
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device bef
CriticalCVSS 10.0No exploitEPSS 13%digital alert systems · dasdec easJun 30, 2013
- CVE-2014-356643Plan
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
LowCVSS 3.4WeaponizedEPSS 100%openssl · opensslOct 14, 2014
- CVE-2014-787843Plan
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node im
CriticalCVSS 10.0No exploitEPSS 10%hp · helion cloud development platformNov 13, 2014
- CVE-2008-510043Plan
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the p
CriticalCVSS 10.0No exploitEPSS 8%microsoft · .net frameworkNov 17, 2008
- CVE-2004-276142Plan
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac
CriticalCVSS 9.8Proof of conceptEPSS 10%ietf · md5Jan 5, 2009
- CVE-2011-468442Plan
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne
CriticalCVSS 10.0Proof of conceptEPSS 6%opera · opera browserDec 7, 2011
- CVE-2007-652142Plan
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
CriticalCVSS 10.0No exploitEPSS 5%opera · opera browserDec 24, 2007
- CVE-2013-478741Plan
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execut
CriticalCVSS 9.3Proof of conceptEPSS 13%google · androidJul 9, 2013
- CVE-2006-027041Plan
Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impac
CriticalCVSS 10.0No exploitEPSS 5%oracle · database serverJan 18, 2006
- CVE-2011-093541Plan
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to
CriticalCVSS 10.0No exploitEPSS 4%cisco · iosApr 14, 2011
- CVE-2013-695241Plan
The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware u
CriticalCVSS 10.0No exploitEPSS 4%belkin · wemo home automation firmwareFeb 22, 2014
- CVE-2008-682441Plan
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it
CriticalCVSS 10.0Proof of conceptEPSS 4%a-link · wl54ap2Jun 4, 2009
- CVE-2009-147341Plan
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firm
CriticalCVSS 10.0No exploitEPSS 3%aten · kh1516i ip kvm switchMay 27, 2009
- CVE-2013-683841Plan
An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usi
CriticalCVSS 10.0No exploitEPSS 3%enghouseinteractive · ivr proJan 27, 2014
- CVE-2008-725241Plan
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and at
CriticalCVSS 10.0No exploitEPSS 3%phpmyadmin · phpmyadminJan 19, 2010
- CVE-2006-598241Plan
SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to
CriticalCVSS 10.0No exploitEPSS 3%biba software · seleniumserver ftp serverNov 20, 2006