Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2018-5462

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have an SSL incorrect hostname certificate vulnerability this could allow an attacker to gain unauthorized access to r…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5458

Published Mar 26, 2018

Philips IntelliSpace Portal all versions of 8.0.x, and 7.0.x have a vulnerability using SSL legacy encryption that could allow an attacker to gain unauthorized access to resources…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2903

Published Oct 6, 2017

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SS…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8878

Published Sep 28, 2017

KDE KMail does not encrypt attachments in emails when "automatic encryption" is enabled, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4667

Published Sep 25, 2017

The encryption library in Cisco IOS Software 15.2(1)T, 15.2(1)T1, and 15.2(2)T, Cisco NX-OS in Cisco MDS 9222i Multiservice Modular Switch, Cisco MDS 9000 18/4-Port Multiservice M…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8686

Published Sep 19, 2017

CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP i…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2014-8684

Published Sep 19, 2017

CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object inject…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-7808

Published Sep 15, 2017

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by l…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6766

Published Aug 7, 2017

A vulnerability in the Secure Sockets Layer (SSL) Decryption and Inspection feature of Cisco Firepower System Software 5.4.0, 5.4.1, 6.0.0, 6.1.0, 6.2.0, 6.2.1, and 6.2.2 could al…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-9107

Published Aug 4, 2017

Zoho ManageEngine OpManager 11 through 12.2 uses a custom encryption algorithm to protect the credential used to access the monitored devices. The implemented algorithm doesn't us…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7812

Published Aug 2, 2017

The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker to downgrade the communication between the app and the ser…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-0736

Published Jul 27, 2017

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8013

Published Jul 25, 2017

s2k.js in OpenPGP.js will decrypt arbitrary messages regardless of passphrase for crafted PGP keys which allows remote attackers to bypass authentication if message decryption is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10376

Published May 28, 2017

Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plainte…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-9003

Published May 16, 2017

In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3204

Published Apr 4, 2017

The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly re…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7585

Published Apr 2, 2017

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8234

Published Mar 29, 2017

The image signature algorithm in OpenStack Glance 11.0.0 allows remote attackers to bypass the signature verification process via a crafted image, which triggers an MD5 collision.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8989

Published Mar 14, 2017

Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more ea…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4056

Published Feb 21, 2017

The System Library in VCE Vision Intelligent Operations before 2.6.5 does not properly implement cryptography, which makes it easier for local users to discover credentials by lev…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6329

Published Jan 31, 2017

OpenVPN, when using a 64-bit block cipher, makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demons…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 251-275 of 2,510 CVEsPage 11 of 101