Перейти к содержимому
Noroxi

CWE-310 · 2 325 записей

Cryptographic Issues

CVE этого класса

2 325 записей

  • CVE-2014-8684
    61На этой неделе

    CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and

    КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %

    codeigniter · codeigniter19 сент. 2017 г.

  • CVE-2014-8686
    50В плане

    CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch

    КритическаяCVSS 9,8Готовый эксплойтEPSS 37 %

    codeigniter · codeigniter19 сент. 2017 г.

  • CVE-2012-1803
    49В плане

    RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the b

    ВысокаяCVSS 8,5Готовый эксплойтEPSS 49 %

    siemens · ruggedcom rugged operating system27 апр. 2012 г.

  • CVE-2015-0204
    47В плане

    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL se

    СредняяCVSS 4,3Proof of conceptEPSS 99 %

    openssl · openssl8 янв. 2015 г.

  • CVE-2014-7228
    47В плане

    Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 55 %

    joomla · joomla\!3 нояб. 2014 г.

  • CVE-2009-4655
    45В плане

    The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack ses

    ВысокаяCVSS 7,5Готовый эксплойтEPSS 51 %

    novell · edirectory26 февр. 2010 г.

  • CVE-2016-0736
    45В плане

    In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly

    ВысокаяCVSS 7,5Proof of conceptEPSS 49 %

    apache · http server27 июл. 2017 г.

  • CVE-2015-4000
    44В плане

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E

    НизкаяCVSS 3,7Готовый эксплойтEPSS 100 %

    openssl · openssl20 мая 2015 г.

  • CVE-2007-5863
    44В плане

    Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between

    КритическаяCVSS 9,3Готовый эксплойтEPSS 23 %

    apple · mac os x19 дек. 2007 г.

  • CVE-2013-0137
    44В плане

    The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device bef

    КритическаяCVSS 10,0Эксплойта нетEPSS 13 %

    digital alert systems · dasdec eas30 июн. 2013 г.

  • CVE-2014-3566
    43В плане

    The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man

    НизкаяCVSS 3,4Готовый эксплойтEPSS 100 %

    openssl · openssl14 окт. 2014 г.

  • CVE-2014-7878
    43В плане

    The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node im

    КритическаяCVSS 10,0Эксплойта нетEPSS 10 %

    hp · helion cloud development platform13 нояб. 2014 г.

  • CVE-2008-5100
    43В плане

    The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the p

    КритическаяCVSS 10,0Эксплойта нетEPSS 8 %

    microsoft · .net framework17 нояб. 2008 г.

  • CVE-2004-2761
    42В плане

    The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac

    КритическаяCVSS 9,8Proof of conceptEPSS 10 %

    ietf · md55 янв. 2009 г.

  • CVE-2011-4684
    42В плане

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne

    КритическаяCVSS 10,0Proof of conceptEPSS 6 %

    opera · opera browser7 дек. 2011 г.

  • CVE-2007-6521
    42В плане

    Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    opera · opera browser24 дек. 2007 г.

  • CVE-2013-4787
    41В плане

    Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execut

    КритическаяCVSS 9,3Proof of conceptEPSS 13 %

    google · android9 июл. 2013 г.

  • CVE-2006-0270
    41В плане

    Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impac

    КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

    oracle · database server18 янв. 2006 г.

  • CVE-2011-0935
    41В плане

    The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    cisco · ios14 апр. 2011 г.

  • CVE-2013-6952
    41В плане

    The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware u

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    belkin · wemo home automation firmware22 февр. 2014 г.

  • CVE-2008-6824
    41В плане

    The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it

    КритическаяCVSS 10,0Proof of conceptEPSS 4 %

    a-link · wl54ap24 июн. 2009 г.

  • CVE-2009-1473
    41В плане

    The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firm

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    aten · kh1516i ip kvm switch27 мая 2009 г.

  • CVE-2013-6838
    41В плане

    An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usi

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    enghouseinteractive · ivr pro27 янв. 2014 г.

  • CVE-2008-7252
    41В плане

    libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and at

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    phpmyadmin · phpmyadmin19 янв. 2010 г.

  • CVE-2006-5982
    41В плане

    SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    biba software · seleniumserver ftp server20 нояб. 2006 г.

Все классы уязвимостей