CWE-320 · 88 kayıt
Key Management Errors
Bu sınıftaki CVE’ler
88 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2015-0936Silahlaştırılmış | Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtaiceragon · fibeair ip-10 firmware · CWE-320 | Kritik9,8 | — | %78,1 | 1 Haz 2017 |
45Planlayın | CVE-2018-0732İstismar yok | Client DoS due to large DH parameteropenssl · openssl · CWE-320 | Yüksek7,5 | — | %48,8 | 12 Haz 2018 |
41Planlayın | CVE-2018-0124İstismar yok | A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protectioncisco · unified communications domain manager · CWE-320 | Kritik9,8 | — | %5,1 | 21 Şub 2018 |
39İzleyin | CVE-2016-10467İstismar yok | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, Squalcomm · sd 210 firmware · CWE-320 | Kritik9,8 | — | %1,2 | 18 Nis 2018 |
39İzleyin | CVE-2016-10421İstismar yok | In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MDqualcomm · mdm9206 firmware · CWE-320 | Kritik9,8 | — | %1,2 | 18 Nis 2018 |
39İzleyin | CVE-2015-4166İstismar yok | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectocloudera · key trustee server · CWE-320 | Kritik9,8 | — | %0,7 | 23 Mar 2017 |
36İzleyin | CVE-2015-8542İstismar yok | An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.open-xchange · ox guard · CWE-320 | Yüksek8,8 | — | %2,2 | 15 Ara 2016 |
36İzleyin | CVE-2019-5672İstismar yok | NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Snvidia · jetson tx1 · CWE-320 | Kritik9,1 | — | %1,4 | 11 Nis 2019 |
34İzleyin | CVE-2015-0839İstismar yok | The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by hp · linux imaging and printing · CWE-320 | Yüksek8,1 | — | %6,3 | 2 Ağu 2017 |
33İzleyin | CVE-2026-56254İstismar yok | capacitor-updater - End-to-End Encryption Bypass via Private Key Distributioncapacitor-updater · capacitor-updater · CWE-320 | Yüksek8,3 | — | %0,2 | 10 Tem 2026 |
31İzleyin | CVE-2019-9894İstismar yok | A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.putty · putty · CWE-320 | Yüksek7,5 | — | %2,4 | 21 Mar 2019 |
31İzleyin | CVE-2018-9234İstismar yok | GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in agnupg · gnupg · CWE-320 | Yüksek7,5 | — | %2,0 | 3 Nis 2018 |
31İzleyin | CVE-2015-0153İstismar yok | D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage dlink · dir-815 firmware · CWE-320 | Yüksek7,5 | — | %1,9 | 12 Nis 2018 |
31İzleyin | CVE-2016-6886İstismar yok | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) viamatrixssl · matrixssl · CWE-320 | Yüksek7,5 | — | %1,7 | 13 Oca 2017 |
31İzleyin | CVE-2016-2880İstismar yok | IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.ibm · qradar security information and event manager · CWE-320 | Yüksek7,8 | — | %0,2 | 1 Mar 2017 |
30İzleyin | CVE-2013-2233İstismar yok | Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.redhat · ansible · CWE-320 | Yüksek7,4 | — | %1,9 | 4 May 2018 |
30İzleyin | CVE-2015-7503İstismar yok | Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSAzend · zend framework · CWE-320 | Yüksek7,5 | — | %1,4 | 10 Eki 2017 |
30İzleyin | CVE-2015-1316İstismar yok | Juju Joyent provider uploads user's private ssh key by defaultcanonical · juju · CWE-320 | Yüksek7,5 | — | %1,2 | 22 Nis 2019 |
30İzleyin | CVE-2021-26322İstismar yok | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.amd · epyc 7601 firmware · CWE-320 | Yüksek7,5 | — | %1,0 | 16 Kas 2021 |
30İzleyin | CVE-2017-13887İstismar yok | In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.apple · mac os x · CWE-320 | Yüksek7,5 | — | %0,8 | 11 Oca 2019 |
30İzleyin | CVE-2016-6879İstismar yok | The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging abotan project · botan · CWE-320 | Yüksek7,5 | — | %0,6 | 10 Nis 2017 |
29İzleyin | CVE-2019-12621İstismar yok | Cisco HyperFlex Static SSL Key Vulnerabilitycisco · hyperflex hx220c m5 firmware · CWE-320 | Yüksek7,4 | — | %0,4 | 21 Ağu 2019 |
29İzleyin | CVE-2024-36391İstismar yok | MileSight DeviceHub - CWE-320: Key Management Errorsmilesight · devicehub · CWE-320 | Yüksek7,4 | — | %0,4 | 2 Haz 2024 |
28İzleyin | CVE-2014-2361İstismar yok | OleumTech WIO Family Key Management Errorsoleumtech · sensor wireless i\/o module · CWE-320 | Yüksek7,2 | — | %0,4 | 24 Tem 2014 |
28İzleyin | CVE-2023-21626İstismar yok | Improper Authentication in HLOS.qualcomm · apq8009 firmware · CWE-320 | Yüksek7,1 | — | %0,1 | 8 Ağu 2023 |
- CVE-2015-093662Bu hafta
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remote attackers to obtai
KritikCVSS 9,8SilahlaştırılmışEPSS %78ceragon · fibeair ip-10 firmware1 Haz 2017
- CVE-2018-073245Planlayın
Client DoS due to large DH parameter
YüksekCVSS 7,5İstismar yokEPSS %49openssl · openssl12 Haz 2018
- CVE-2018-012441Planlayın
A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protection
KritikCVSS 9,8İstismar yokEPSS %5cisco · unified communications domain manager21 Şub 2018
- CVE-2016-1046739İzleyin
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 210/SD 212/SD 205, S
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · sd 210 firmware18 Nis 2018
- CVE-2016-1042139İzleyin
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9615, MD
KritikCVSS 9,8İstismar yokEPSS %1qualcomm · mdm9206 firmware18 Nis 2018
- CVE-2015-416639İzleyin
Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vecto
KritikCVSS 9,8İstismar yokEPSS %1cloudera · key trustee server23 Mar 2017
- CVE-2015-854236İzleyin
An issue was discovered in Open-Xchange Guard before 2.2.0-rev8.
YüksekCVSS 8,8İstismar yokEPSS %2open-xchange · ox guard15 Ara 2016
- CVE-2019-567236İzleyin
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the S
KritikCVSS 9,1İstismar yokEPSS %1nvidia · jetson tx111 Nis 2019
- CVE-2015-083934İzleyin
The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers to execute arbitrary code by
YüksekCVSS 8,1İstismar yokEPSS %6hp · linux imaging and printing2 Ağu 2017
- CVE-2026-5625433İzleyin
capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution
YüksekCVSS 8,3İstismar yokEPSS %0capacitor-updater · capacitor-updater10 Tem 2026
- CVE-2019-989431İzleyin
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
YüksekCVSS 7,5İstismar yokEPSS %2putty · putty21 Mar 2019
- CVE-2018-923431İzleyin
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in a
YüksekCVSS 7,5İstismar yokEPSS %2gnupg · gnupg3 Nis 2018
- CVE-2015-015331İzleyin
D-Link DIR-815 devices with firmware before 2.07.B01 allow remote attackers to obtain sensitive information by leveraging cleartext storage
YüksekCVSS 7,5İstismar yokEPSS %2dlink · dir-815 firmware12 Nis 2018
- CVE-2016-688631İzleyin
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via
YüksekCVSS 7,5İstismar yokEPSS %2matrixssl · matrixssl13 Oca 2017
- CVE-2016-288031İzleyin
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user.
YüksekCVSS 7,8İstismar yokEPSS %0ibm · qradar security information and event manager1 Mar 2017
- CVE-2013-223330İzleyin
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
YüksekCVSS 7,4İstismar yokEPSS %2redhat · ansible4 May 2018
- CVE-2015-750330İzleyin
Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA
YüksekCVSS 7,5İstismar yokEPSS %1zend · zend framework10 Eki 2017
- CVE-2015-131630İzleyin
Juju Joyent provider uploads user's private ssh key by default
YüksekCVSS 7,5İstismar yokEPSS %1canonical · juju22 Nis 2019
- CVE-2021-2632230İzleyin
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
YüksekCVSS 7,5İstismar yokEPSS %1amd · epyc 7601 firmware16 Kas 2021
- CVE-2017-1388730İzleyin
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
YüksekCVSS 7,5İstismar yokEPSS %1apple · mac os x11 Oca 2019
- CVE-2016-687930İzleyin
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a
YüksekCVSS 7,5İstismar yokEPSS %1botan project · botan10 Nis 2017
- CVE-2019-1262129İzleyin
Cisco HyperFlex Static SSL Key Vulnerability
YüksekCVSS 7,4İstismar yokEPSS %0cisco · hyperflex hx220c m5 firmware21 Ağu 2019
- CVE-2024-3639129İzleyin
MileSight DeviceHub - CWE-320: Key Management Errors
YüksekCVSS 7,4İstismar yokEPSS %0milesight · devicehub2 Haz 2024
- CVE-2014-236128İzleyin
OleumTech WIO Family Key Management Errors
YüksekCVSS 7,2İstismar yokEPSS %0oleumtech · sensor wireless i\/o module24 Tem 2014
- CVE-2023-2162628İzleyin
Improper Authentication in HLOS.
YüksekCVSS 7,1İstismar yokEPSS %0qualcomm · apq8009 firmware8 Ağu 2023