Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,514 CVEs tagged with CWE-31058 Critical, 302 High, 2,014 Medium, 140 Low, 0 Unrated.

CVE-2016-0904

Published Sep 21, 2016

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0897

Published Sep 18, 2016

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecif…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5430

Published Sep 3, 2016

The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote atta…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6257

Published Aug 2, 2016

The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not…

CVSS 6.5 · Medium

CVE-2016-5672

Published Aug 1, 2016

Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5774

Published Jul 12, 2016

The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vecto…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2364

Published Jun 20, 2016

The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5433

Published Jun 17, 2016

Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4005

Published Jun 13, 2016

The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIR…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4524

Published Jun 10, 2016

ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4511

Published Jun 10, 2016

ABB PCM600 before 2.7 uses an improper hash algorithm for the main application password, which makes it easier for local users to obtain sensitive cleartext information by leverag…

CVSS 2.8 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1902

Published Jun 1, 2016

The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8867

Published May 22, 2016

The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseu…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9742

Published May 13, 2016

The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptog…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2107

Published May 5, 2016

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obt…

CVSS 5.9 · Medium
evidence mentions
10
Buzz score
32.0

CVE-2000-1254

Published May 5, 2016

crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2053

Published May 2, 2016

The asn1_ber_decoder function in lib/asn1_decoder.c in the Linux kernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2113

Published Apr 25, 2016

Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof LDAPS an…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 301-325 of 2,514 CVEsPage 13 of 101