Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2016-1919

Published Jan 27, 2017

Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10139

Published Jan 13, 2017

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and com.adups.fota.sysoper. In the…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10138

Published Jan 13, 2017

An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a system app and cannot be disabled b…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10137

Published Jan 13, 2017

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name o…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10136

Published Jan 13, 2017

An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name o…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10099

Published Jan 2, 2017

Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of archives), potentially allowing an attacker to spoof the lis…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7270

Published Dec 20, 2016

The Data Provider for SQL Server in Microsoft .NET Framework 4.6.2 mishandles a developer-supplied key, which allows remote attackers to bypass the Always Encrypted protection mec…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7439

Published Dec 13, 2016

The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7438

Published Dec 13, 2016

The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9847

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. When the user does not specify a blowfish_secret key for encrypting cookies, phpMyAdmin generates one at runtime. A vulnerability was report…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6606

Published Dec 11, 2016

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has ac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2953

Published Nov 30, 2016

IBM Connections 4.0 through CR4, 4.5 through CR5, and 5.0 before CR4 does not require SSL, which allows remote attackers to obtain sensitive cleartext information by sniffing the…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2951

Published Nov 30, 2016

IBM BigFix Remote Control before 9.1.3 does not properly set the default encryption strength, which makes it easier for remote attackers to defeat cryptographic protection mechani…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-8889

Published Oct 28, 2016

In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information including private keys and the…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6550

Published Oct 5, 2016

The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sens…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4754

Published Sep 25, 2016

ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-0904

Published Sep 21, 2016

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0897

Published Sep 18, 2016

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecif…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 276-300 of 2,510 CVEsPage 12 of 101