İçeriğe atla
Noroxi

CWE-310 · 2.325 kayıt

Cryptographic Issues

Bu sınıftaki CVE’ler

2.325 kayıt

  • CVE-2014-8684
    61Bu hafta

    CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and

    KritikCVSS 9,8SilahlaştırılmışEPSS %72

    codeigniter · codeigniter19 Eyl 2017

  • CVE-2014-8686
    50Planlayın

    CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch

    KritikCVSS 9,8SilahlaştırılmışEPSS %37

    codeigniter · codeigniter19 Eyl 2017

  • CVE-2012-1803
    49Planlayın

    RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the b

    YüksekCVSS 8,5SilahlaştırılmışEPSS %49

    siemens · ruggedcom rugged operating system27 Nis 2012

  • CVE-2015-0204
    47Planlayın

    The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL se

    OrtaCVSS 4,3Kavram kanıtıEPSS %99

    openssl · openssl8 Oca 2015

  • CVE-2014-7228
    47Planlayın

    Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!

    YüksekCVSS 7,5SilahlaştırılmışEPSS %55

    joomla · joomla\!3 Kas 2014

  • CVE-2009-4655
    45Planlayın

    The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack ses

    YüksekCVSS 7,5SilahlaştırılmışEPSS %51

    novell · edirectory26 Şub 2010

  • CVE-2016-0736
    45Planlayın

    In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly

    YüksekCVSS 7,5Kavram kanıtıEPSS %49

    apache · http server27 Tem 2017

  • CVE-2015-4000
    44Planlayın

    The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E

    DüşükCVSS 3,7SilahlaştırılmışEPSS %100

    openssl · openssl20 May 2015

  • CVE-2007-5863
    44Planlayın

    Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between

    KritikCVSS 9,3SilahlaştırılmışEPSS %23

    apple · mac os x19 Ara 2007

  • CVE-2013-0137
    44Planlayın

    The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device bef

    KritikCVSS 10,0İstismar yokEPSS %13

    digital alert systems · dasdec eas30 Haz 2013

  • CVE-2014-3566
    43Planlayın

    The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man

    DüşükCVSS 3,4SilahlaştırılmışEPSS %100

    openssl · openssl14 Eki 2014

  • CVE-2014-7878
    43Planlayın

    The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node im

    KritikCVSS 10,0İstismar yokEPSS %10

    hp · helion cloud development platform13 Kas 2014

  • CVE-2008-5100
    43Planlayın

    The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the p

    KritikCVSS 10,0İstismar yokEPSS %8

    microsoft · .net framework17 Kas 2008

  • CVE-2004-2761
    42Planlayın

    The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    ietf · md55 Oca 2009

  • CVE-2011-4684
    42Planlayın

    Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne

    KritikCVSS 10,0Kavram kanıtıEPSS %6

    opera · opera browser7 Ara 2011

  • CVE-2007-6521
    42Planlayın

    Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.

    KritikCVSS 10,0İstismar yokEPSS %5

    opera · opera browser24 Ara 2007

  • CVE-2013-4787
    41Planlayın

    Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execut

    KritikCVSS 9,3Kavram kanıtıEPSS %13

    google · android9 Tem 2013

  • CVE-2006-0270
    41Planlayın

    Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impac

    KritikCVSS 10,0İstismar yokEPSS %5

    oracle · database server18 Oca 2006

  • CVE-2011-0935
    41Planlayın

    The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to

    KritikCVSS 10,0İstismar yokEPSS %4

    cisco · ios14 Nis 2011

  • CVE-2013-6952
    41Planlayın

    The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware u

    KritikCVSS 10,0İstismar yokEPSS %4

    belkin · wemo home automation firmware22 Şub 2014

  • CVE-2008-6824
    41Planlayın

    The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it

    KritikCVSS 10,0Kavram kanıtıEPSS %4

    a-link · wl54ap24 Haz 2009

  • CVE-2009-1473
    41Planlayın

    The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firm

    KritikCVSS 10,0İstismar yokEPSS %3

    aten · kh1516i ip kvm switch27 May 2009

  • CVE-2013-6838
    41Planlayın

    An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usi

    KritikCVSS 10,0İstismar yokEPSS %3

    enghouseinteractive · ivr pro27 Oca 2014

  • CVE-2008-7252
    41Planlayın

    libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and at

    KritikCVSS 10,0İstismar yokEPSS %3

    phpmyadmin · phpmyadmin19 Oca 2010

  • CVE-2006-5982
    41Planlayın

    SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to

    KritikCVSS 10,0İstismar yokEPSS %3

    biba software · seleniumserver ftp server20 Kas 2006

Tüm zafiyet sınıfları