Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,514 CVEs tagged with CWE-31058 Critical, 302 High, 2,014 Medium, 140 Low, 0 Unrated.

CVE-2012-2417

Published Jun 17, 2012

PyCrypto before 2.6 does not produce appropriate prime numbers when using an ElGamal scheme to generate a key, which reduces the signature space or public key space and makes it e…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3287

Published Jun 13, 2012

Poul-Henning Kamp md5crypt has insufficient algorithmic complexity and a consequently short runtime, which makes it easier for context-dependent attackers to discover cleartext pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1251

Published Jun 4, 2012

Opera before 9.63 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0655

Published May 11, 2012

libsecurity in Apple Mac OS X before 10.7.4 does not properly restrict the length of RSA keys within X.509 certificates, which makes it easier for remote attackers to defeat crypt…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0732

Published May 3, 2012

The Enterprise Console client in IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2162

Published May 1, 2012

The Web Server Plug-in in IBM WebSphere Application Server (WAS) 8.0 and earlier uses unencrypted HTTP communication after expiration of the plugin-key.kdb password, which allows…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0863

Published Apr 30, 2012

Mumble 1.2.3 and earlier uses world-readable permissions for .local/share/data/Mumble/.mumble.sqlite files in home directories, which might allow local users to obtain a cleartext…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1803

Published Apr 28, 2012

RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1244

Published Apr 27, 2012

The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2405

Published Apr 22, 2012

Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0726

Published Apr 22, 2012

The default configuration of TLS in IBM Tivoli Directory Server (TDS) 6.3 and earlier supports the (1) NULL-MD5 and (2) NULL-SHA ciphers, which allows remote attackers to trigger…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0386

Published Mar 29, 2012

The SSHv2 implementation in Cisco IOS 12.2, 12.4, 15.0, 15.1, and 15.2 and IOS XE 2.3.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S allows remote attackers to cause a de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0381

Published Mar 29, 2012

The IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.2…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1573

Published Mar 26, 2012

gnutls_cipher.c in libgnutls in GnuTLS before 2.12.17 and 3.x before 3.0.15 does not properly handle data encrypted with a block cipher, which allows remote attackers to cause a d…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0884

Published Mar 13, 2012

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3444

Published Feb 2, 2012

Address Book in Apple Mac OS X before 10.7.3 automatically switches to unencrypted sessions upon failure of encrypted connections, which allows remote attackers to read CardDAV da…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4354

Published Jan 27, 2012

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an in…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5064

Published Jan 14, 2012

DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0039

Published Jan 14, 2012

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0390

Published Jan 6, 2012

The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4576

Published Jan 6, 2012

The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4108

Published Jan 6, 2012

The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,201-2,225 of 2,514 CVEsPage 89 of 101