CWE-310 · 2 325 записей
Cryptographic Issues
CVE этого класса
2 325 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2014-8684Готовый эксплойт | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies andcodeigniter · codeigniter · CWE-310 | Критическая9,8 | — | 71,7 % | 19 сент. 2017 г. |
50В плане | CVE-2014-8686Готовый эксплойт | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption schcodeigniter · codeigniter · CWE-310 | Критическая9,8 | — | 37,2 % | 19 сент. 2017 г. |
49В плане | CVE-2012-1803Готовый эксплойт | RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the bsiemens · ruggedcom rugged operating system · CWE-310 | Высокая8,5 | — | 49,0 % | 27 апр. 2012 г. |
47В плане | CVE-2015-0204Proof of concept | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL seopenssl · openssl · CWE-310 | Средняя4,3 | — | 98,7 % | 8 янв. 2015 г. |
47В плане | CVE-2014-7228Готовый эксплойт | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!joomla · joomla\! · CWE-310 | Высокая7,5 | — | 55,4 % | 3 нояб. 2014 г. |
45В плане | CVE-2009-4655Готовый эксплойт | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sesnovell · edirectory · CWE-310 | Высокая7,5 | — | 50,5 % | 26 февр. 2010 г. |
45В плане | CVE-2016-0736Proof of concept | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possiblyapache · http server · CWE-310 | Высокая7,5 | — | 49,0 % | 27 июл. 2017 г. |
44В плане | CVE-2015-4000Готовый эксплойт | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_Eopenssl · openssl · CWE-310 | Низкая3,7 | — | 99,9 % | 20 мая 2015 г. |
44В плане | CVE-2007-5863Готовый эксплойт | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack betweenapple · mac os x · CWE-310 | Критическая9,3 | — | 23,0 % | 19 дек. 2007 г. |
44В плане | CVE-2013-0137Эксплойта нет | The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device befdigital alert systems · dasdec eas · CWE-310 | Критическая10,0 | — | 13,4 % | 30 июн. 2013 г. |
43В плане | CVE-2014-3566Готовый эксплойт | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Низкая3,4 | — | 100,0 % | 14 окт. 2014 г. |
43В плане | CVE-2014-7878Эксплойта нет | The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node imhp · helion cloud development platform · CWE-310 | Критическая10,0 | — | 10,3 % | 13 нояб. 2014 г. |
43В плане | CVE-2008-5100Эксплойта нет | The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pmicrosoft · .net framework · CWE-310 | Критическая10,0 | — | 8,4 % | 17 нояб. 2008 г. |
42В плане | CVE-2004-2761Proof of concept | The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacietf · md5 · CWE-310 | Критическая9,8 | — | 9,9 % | 5 янв. 2009 г. |
42В плане | CVE-2011-4684Proof of concept | Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corneopera · opera browser · CWE-310 | Критическая10,0 | — | 5,7 % | 7 дек. 2011 г. |
42В плане | CVE-2007-6521Эксплойта нет | Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.opera · opera browser · CWE-310 | Критическая10,0 | — | 5,0 % | 24 дек. 2007 г. |
41В плане | CVE-2013-4787Proof of concept | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to executgoogle · android · CWE-310 | Критическая9,3 | — | 13,4 % | 9 июл. 2013 г. |
41В плане | CVE-2006-0270Эксплойта нет | Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impacoracle · database server · CWE-310 | Критическая10,0 | — | 4,9 % | 18 янв. 2006 г. |
41В плане | CVE-2011-0935Эксплойта нет | The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers tocisco · ios · CWE-310 | Критическая10,0 | — | 4,0 % | 14 апр. 2011 г. |
41В плане | CVE-2013-6952Эксплойта нет | The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware ubelkin · wemo home automation firmware · CWE-310 | Критическая10,0 | — | 3,8 % | 22 февр. 2014 г. |
41В плане | CVE-2008-6824Proof of concept | The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it a-link · wl54ap2 · CWE-310 | Критическая10,0 | — | 3,6 % | 4 июн. 2009 г. |
41В плане | CVE-2009-1473Эксплойта нет | The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmaten · kh1516i ip kvm switch · CWE-310 | Критическая10,0 | — | 3,2 % | 27 мая 2009 г. |
41В плане | CVE-2013-6838Эксплойта нет | An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usienghouseinteractive · ivr pro · CWE-310 | Критическая10,0 | — | 2,8 % | 27 янв. 2014 г. |
41В плане | CVE-2008-7252Эксплойта нет | libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and atphpmyadmin · phpmyadmin · CWE-310 | Критическая10,0 | — | 2,7 % | 19 янв. 2010 г. |
41В плане | CVE-2006-5982Эксплойта нет | SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to biba software · seleniumserver ftp server · CWE-310 | Критическая10,0 | — | 2,7 % | 20 нояб. 2006 г. |
- CVE-2014-868461На этой неделе
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and
КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %codeigniter · codeigniter19 сент. 2017 г.
- CVE-2014-868650В плане
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch
КритическаяCVSS 9,8Готовый эксплойтEPSS 37 %codeigniter · codeigniter19 сент. 2017 г.
- CVE-2012-180349В плане
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the b
ВысокаяCVSS 8,5Готовый эксплойтEPSS 49 %siemens · ruggedcom rugged operating system27 апр. 2012 г.
- CVE-2015-020447В плане
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL se
СредняяCVSS 4,3Proof of conceptEPSS 99 %openssl · openssl8 янв. 2015 г.
- CVE-2014-722847В плане
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!
ВысокаяCVSS 7,5Готовый эксплойтEPSS 55 %joomla · joomla\!3 нояб. 2014 г.
- CVE-2009-465545В плане
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack ses
ВысокаяCVSS 7,5Готовый эксплойтEPSS 51 %novell · edirectory26 февр. 2010 г.
- CVE-2016-073645В плане
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly
ВысокаяCVSS 7,5Proof of conceptEPSS 49 %apache · http server27 июл. 2017 г.
- CVE-2015-400044В плане
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E
НизкаяCVSS 3,7Готовый эксплойтEPSS 100 %openssl · openssl20 мая 2015 г.
- CVE-2007-586344В плане
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between
КритическаяCVSS 9,3Готовый эксплойтEPSS 23 %apple · mac os x19 дек. 2007 г.
- CVE-2013-013744В плане
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device bef
КритическаяCVSS 10,0Эксплойта нетEPSS 13 %digital alert systems · dasdec eas30 июн. 2013 г.
- CVE-2014-356643В плане
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
НизкаяCVSS 3,4Готовый эксплойтEPSS 100 %openssl · openssl14 окт. 2014 г.
- CVE-2014-787843В плане
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node im
КритическаяCVSS 10,0Эксплойта нетEPSS 10 %hp · helion cloud development platform13 нояб. 2014 г.
- CVE-2008-510043В плане
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the p
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %microsoft · .net framework17 нояб. 2008 г.
- CVE-2004-276142В плане
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac
КритическаяCVSS 9,8Proof of conceptEPSS 10 %ietf · md55 янв. 2009 г.
- CVE-2011-468442В плане
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne
КритическаяCVSS 10,0Proof of conceptEPSS 6 %opera · opera browser7 дек. 2011 г.
- CVE-2007-652142В плане
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %opera · opera browser24 дек. 2007 г.
- CVE-2013-478741В плане
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execut
КритическаяCVSS 9,3Proof of conceptEPSS 13 %google · android9 июл. 2013 г.
- CVE-2006-027041В плане
Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impac
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %oracle · database server18 янв. 2006 г.
- CVE-2011-093541В плане
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %cisco · ios14 апр. 2011 г.
- CVE-2013-695241В плане
The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware u
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %belkin · wemo home automation firmware22 февр. 2014 г.
- CVE-2008-682441В плане
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it
КритическаяCVSS 10,0Proof of conceptEPSS 4 %a-link · wl54ap24 июн. 2009 г.
- CVE-2009-147341В плане
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firm
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %aten · kh1516i ip kvm switch27 мая 2009 г.
- CVE-2013-683841В плане
An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usi
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %enghouseinteractive · ivr pro27 янв. 2014 г.
- CVE-2008-725241В плане
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and at
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %phpmyadmin · phpmyadmin19 янв. 2010 г.
- CVE-2006-598241В плане
SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %biba software · seleniumserver ftp server20 нояб. 2006 г.