İçeriğe atla
Noroxi

CWE-320 · 88 kayıt

Key Management Errors

Bu sınıftaki CVE’ler

88 kayıt

  • CVE-2015-0936
    62Bu hafta

    Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtai

    KritikCVSS 9,8SilahlaştırılmışEPSS %78

    ceragon · fibeair ip-10 firmware1 Haz 2017

  • CVE-2018-0732
    45Planlayın

    Client DoS due to large DH parameter

    YüksekCVSS 7,5İstismar yokEPSS %49

    openssl · openssl12 Haz 2018

  • CVE-2018-0124
    41Planlayın

    A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protection

    KritikCVSS 9,8İstismar yokEPSS %5

    cisco · unified communications domain manager21 Şub 2018

  • CVE-2016-10467
    39İzleyin

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, S

    KritikCVSS 9,8İstismar yokEPSS %1

    qualcomm · sd 210 firmware18 Nis 2018

  • CVE-2016-10421
    39İzleyin

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD

    KritikCVSS 9,8İstismar yokEPSS %1

    qualcomm · mdm9206 firmware18 Nis 2018

  • CVE-2015-4166
    39İzleyin

    Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vecto

    KritikCVSS 9,8İstismar yokEPSS %1

    cloudera · key trustee server23 Mar 2017

  • CVE-2015-8542
    36İzleyin

    An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.

    YüksekCVSS 8,8İstismar yokEPSS %2

    open-xchange · ox guard15 Ara 2016

  • CVE-2019-5672
    36İzleyin

    NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the S

    KritikCVSS 9,1İstismar yokEPSS %1

    nvidia · jetson tx111 Nis 2019

  • CVE-2015-0839
    34İzleyin

    The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by

    YüksekCVSS 8,1İstismar yokEPSS %6

    hp · linux imaging and printing2 Ağu 2017

  • CVE-2026-56254
    33İzleyin

    capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution

    YüksekCVSS 8,3İstismar yokEPSS %0

    capacitor-updater · capacitor-updater10 Tem 2026

  • CVE-2019-9894
    31İzleyin

    A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.

    YüksekCVSS 7,5İstismar yokEPSS %2

    putty · putty21 Mar 2019

  • CVE-2018-9234
    31İzleyin

    GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in a

    YüksekCVSS 7,5İstismar yokEPSS %2

    gnupg · gnupg3 Nis 2018

  • CVE-2015-0153
    31İzleyin

    D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage

    YüksekCVSS 7,5İstismar yokEPSS %2

    dlink · dir-815 firmware12 Nis 2018

  • CVE-2016-6886
    31İzleyin

    The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via

    YüksekCVSS 7,5İstismar yokEPSS %2

    matrixssl · matrixssl13 Oca 2017

  • CVE-2016-2880
    31İzleyin

    IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.

    YüksekCVSS 7,8İstismar yokEPSS %0

    ibm · qradar security information and event manager1 Mar 2017

  • CVE-2013-2233
    30İzleyin

    Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.

    YüksekCVSS 7,4İstismar yokEPSS %2

    redhat · ansible4 May 2018

  • CVE-2015-7503
    30İzleyin

    Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA

    YüksekCVSS 7,5İstismar yokEPSS %1

    zend · zend framework10 Eki 2017

  • CVE-2015-1316
    30İzleyin

    Juju Joyent provider uploads user's private ssh key by default

    YüksekCVSS 7,5İstismar yokEPSS %1

    canonical · juju22 Nis 2019

  • CVE-2021-26322
    30İzleyin

    Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

    YüksekCVSS 7,5İstismar yokEPSS %1

    amd · epyc 7601 firmware16 Kas 2021

  • CVE-2017-13887
    30İzleyin

    In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.

    YüksekCVSS 7,5İstismar yokEPSS %1

    apple · mac os x11 Oca 2019

  • CVE-2016-6879
    30İzleyin

    The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a

    YüksekCVSS 7,5İstismar yokEPSS %1

    botan project · botan10 Nis 2017

  • CVE-2019-12621
    29İzleyin

    Cisco HyperFlex Static SSL Key Vulnerability

    YüksekCVSS 7,4İstismar yokEPSS %0

    cisco · hyperflex hx220c m5 firmware21 Ağu 2019

  • CVE-2024-36391
    29İzleyin

    MileSight DeviceHub - CWE-320: Key Management Errors

    YüksekCVSS 7,4İstismar yokEPSS %0

    milesight · devicehub2 Haz 2024

  • CVE-2014-2361
    28İzleyin

    OleumTech WIO Family Key Management Errors

    YüksekCVSS 7,2İstismar yokEPSS %0

    oleumtech · sensor wireless i\/o module24 Tem 2014

  • CVE-2023-21626
    28İzleyin

    Improper Authentication in HLOS.

    YüksekCVSS 7,1İstismar yokEPSS %0

    qualcomm · apq8009 firmware8 Ağu 2023

Tüm zafiyet sınıfları