CWE-310 · 2.325 kayıt
Cryptographic Issues
Bu sınıftaki CVE’ler
2.325 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2014-8684Silahlaştırılmış | CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies andcodeigniter · codeigniter · CWE-310 | Kritik9,8 | — | %71,7 | 19 Eyl 2017 |
50Planlayın | CVE-2014-8686Silahlaştırılmış | CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption schcodeigniter · codeigniter · CWE-310 | Kritik9,8 | — | %37,2 | 19 Eyl 2017 |
49Planlayın | CVE-2012-1803Silahlaştırılmış | RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the bsiemens · ruggedcom rugged operating system · CWE-310 | Yüksek8,5 | — | %49,0 | 27 Nis 2012 |
47Planlayın | CVE-2015-0204Kavram kanıtı | The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL seopenssl · openssl · CWE-310 | Orta4,3 | — | %98,7 | 8 Oca 2015 |
47Planlayın | CVE-2014-7228Silahlaştırılmış | Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!joomla · joomla\! · CWE-310 | Yüksek7,5 | — | %55,4 | 3 Kas 2014 |
45Planlayın | CVE-2009-4655Silahlaştırılmış | The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack sesnovell · edirectory · CWE-310 | Yüksek7,5 | — | %50,5 | 26 Şub 2010 |
45Planlayın | CVE-2016-0736Kavram kanıtı | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possiblyapache · http server · CWE-310 | Yüksek7,5 | — | %49,0 | 27 Tem 2017 |
44Planlayın | CVE-2015-4000Silahlaştırılmış | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_Eopenssl · openssl · CWE-310 | Düşük3,7 | — | %99,9 | 20 May 2015 |
44Planlayın | CVE-2007-5863Silahlaştırılmış | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack betweenapple · mac os x · CWE-310 | Kritik9,3 | — | %23,0 | 19 Ara 2007 |
44Planlayın | CVE-2013-0137İstismar yok | The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device befdigital alert systems · dasdec eas · CWE-310 | Kritik10,0 | — | %13,4 | 30 Haz 2013 |
43Planlayın | CVE-2014-3566Silahlaştırılmış | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for manopenssl · openssl · CWE-310 | Düşük3,4 | — | %100,0 | 14 Eki 2014 |
43Planlayın | CVE-2014-7878İstismar yok | The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node imhp · helion cloud development platform · CWE-310 | Kritik10,0 | — | %10,3 | 13 Kas 2014 |
43Planlayın | CVE-2008-5100İstismar yok | The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pmicrosoft · .net framework · CWE-310 | Kritik10,0 | — | %8,4 | 17 Kas 2008 |
42Planlayın | CVE-2004-2761Kavram kanıtı | The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacietf · md5 · CWE-310 | Kritik9,8 | — | %9,9 | 5 Oca 2009 |
42Planlayın | CVE-2011-4684Kavram kanıtı | Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corneopera · opera browser · CWE-310 | Kritik10,0 | — | %5,7 | 7 Ara 2011 |
42Planlayın | CVE-2007-6521İstismar yok | Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.opera · opera browser · CWE-310 | Kritik10,0 | — | %5,0 | 24 Ara 2007 |
41Planlayın | CVE-2013-4787Kavram kanıtı | Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to executgoogle · android · CWE-310 | Kritik9,3 | — | %13,4 | 9 Tem 2013 |
41Planlayın | CVE-2006-0270İstismar yok | Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impacoracle · database server · CWE-310 | Kritik10,0 | — | %4,9 | 18 Oca 2006 |
41Planlayın | CVE-2011-0935İstismar yok | The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers tocisco · ios · CWE-310 | Kritik10,0 | — | %4,0 | 14 Nis 2011 |
41Planlayın | CVE-2013-6952İstismar yok | The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware ubelkin · wemo home automation firmware · CWE-310 | Kritik10,0 | — | %3,8 | 22 Şub 2014 |
41Planlayın | CVE-2008-6824Kavram kanıtı | The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it a-link · wl54ap2 · CWE-310 | Kritik10,0 | — | %3,6 | 4 Haz 2009 |
41Planlayın | CVE-2009-1473İstismar yok | The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmaten · kh1516i ip kvm switch · CWE-310 | Kritik10,0 | — | %3,2 | 27 May 2009 |
41Planlayın | CVE-2013-6838İstismar yok | An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usienghouseinteractive · ivr pro · CWE-310 | Kritik10,0 | — | %2,8 | 27 Oca 2014 |
41Planlayın | CVE-2008-7252İstismar yok | libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and atphpmyadmin · phpmyadmin · CWE-310 | Kritik10,0 | — | %2,7 | 19 Oca 2010 |
41Planlayın | CVE-2006-5982İstismar yok | SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to biba software · seleniumserver ftp server · CWE-310 | Kritik10,0 | — | %2,7 | 20 Kas 2006 |
- CVE-2014-868461Bu hafta
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and
KritikCVSS 9,8SilahlaştırılmışEPSS %72codeigniter · codeigniter19 Eyl 2017
- CVE-2014-868650Planlayın
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption sch
KritikCVSS 9,8SilahlaştırılmışEPSS %37codeigniter · codeigniter19 Eyl 2017
- CVE-2012-180349Planlayın
RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the b
YüksekCVSS 8,5SilahlaştırılmışEPSS %49siemens · ruggedcom rugged operating system27 Nis 2012
- CVE-2015-020447Planlayın
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL se
OrtaCVSS 4,3Kavram kanıtıEPSS %99openssl · openssl8 Oca 2015
- CVE-2014-722847Planlayın
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla!
YüksekCVSS 7,5SilahlaştırılmışEPSS %55joomla · joomla\!3 Kas 2014
- CVE-2009-465545Planlayın
The dhost web service in Novell eDirectory 8.8.5 uses a predictable session cookie, which makes it easier for remote attackers to hijack ses
YüksekCVSS 7,5SilahlaştırılmışEPSS %51novell · edirectory26 Şub 2010
- CVE-2016-073645Planlayın
In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly
YüksekCVSS 7,5Kavram kanıtıEPSS %49apache · http server27 Tem 2017
- CVE-2015-400044Planlayın
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_E
DüşükCVSS 3,7SilahlaştırılmışEPSS %100openssl · openssl20 May 2015
- CVE-2007-586344Planlayın
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between
KritikCVSS 9,3SilahlaştırılmışEPSS %23apple · mac os x19 Ara 2007
- CVE-2013-013744Planlayın
The default configuration of the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device bef
KritikCVSS 10,0İstismar yokEPSS %13digital alert systems · dasdec eas30 Haz 2013
- CVE-2014-356643Planlayın
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man
DüşükCVSS 3,4SilahlaştırılmışEPSS %100openssl · openssl14 Eki 2014
- CVE-2014-787843Planlayın
The Application Lifecycle Service (ALS) in HP Helion Cloud Development Platform 1.0, when a virtual machine is derived from the Seed Node im
KritikCVSS 10,0İstismar yokEPSS %10hp · helion cloud development platform13 Kas 2014
- CVE-2008-510043Planlayın
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the p
KritikCVSS 10,0İstismar yokEPSS %8microsoft · .net framework17 Kas 2008
- CVE-2004-276142Planlayın
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attac
KritikCVSS 9,8Kavram kanıtıEPSS %10ietf · md55 Oca 2009
- CVE-2011-468442Planlayın
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corne
KritikCVSS 10,0Kavram kanıtıEPSS %6opera · opera browser7 Ara 2011
- CVE-2007-652142Planlayın
Unspecified vulnerability in Opera before 9.25 allows remote attackers to execute arbitrary code via crafted TLS certificates.
KritikCVSS 10,0İstismar yokEPSS %5opera · opera browser24 Ara 2007
- CVE-2013-478741Planlayın
Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execut
KritikCVSS 9,3Kavram kanıtıEPSS %13google · android9 Tem 2013
- CVE-2006-027041Planlayın
Unspecified vulnerability in the Transparent Data Encryption (TDE) Wallet component of Oracle Database server 10.2.0.1 has unspecified impac
KritikCVSS 10,0İstismar yokEPSS %5oracle · database server18 Oca 2006
- CVE-2011-093541Planlayın
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to
KritikCVSS 10,0İstismar yokEPSS %4cisco · ios14 Nis 2011
- CVE-2013-695241Planlayın
The Belkin WeMo Home Automation firmware before 3949 has a hardcoded GPG key, which makes it easier for remote attackers to spoof firmware u
KritikCVSS 10,0İstismar yokEPSS %4belkin · wemo home automation firmware22 Şub 2014
- CVE-2008-682441Planlayın
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin account, which makes it
KritikCVSS 10,0Kavram kanıtıEPSS %4a-link · wl54ap24 Haz 2009
- CVE-2009-147341Planlayın
The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firm
KritikCVSS 10,0İstismar yokEPSS %3aten · kh1516i ip kvm switch27 May 2009
- CVE-2013-683841Planlayın
An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when usi
KritikCVSS 10,0İstismar yokEPSS %3enghouseinteractive · ivr pro27 Oca 2014
- CVE-2008-725241Planlayın
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and at
KritikCVSS 10,0İstismar yokEPSS %3phpmyadmin · phpmyadmin19 Oca 2010
- CVE-2006-598241Planlayın
SeleniumServer FTP Server 1.0, and possibly earlier, stores user passwords in plaintext in the Servers directory, which allows attackers to
KritikCVSS 10,0İstismar yokEPSS %3biba software · seleniumserver ftp server20 Kas 2006