Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2010-4007

Published Oct 20, 2010

Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2057

Published Oct 20, 2010

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MA…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3741

Published Oct 5, 2010

The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3075

Published Sep 17, 2010

EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive informat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3074

Published Sep 17, 2010

SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive in…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3073

Published Sep 17, 2010

SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it eas…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3400

Published Sep 15, 2010

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses the current time for se…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3399

Published Sep 15, 2010

The js_InitRandom function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a context pointer in conjunction with…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3171

Published Sep 15, 2010

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seede…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4269

Published Aug 16, 2010

The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of i…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2757

Published Aug 16, 2010

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2967

Published Aug 5, 2010

The loginDefaultEncrypt algorithm in loginLib in Wind River VxWorks before 6.9 does not properly support a large set of distinct possible passwords, which makes it easier for remo…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1377

Published Jun 17, 2010

Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary networ…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2072

Published Jun 16, 2010

Pyftpd 0.8.4 creates log files with predictable names in a temporary directory, which allows local users to cause a denial of service and obtain sensitive information.

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2270

Published Jun 15, 2010

Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0742

Published Jun 3, 2010

The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain Orig…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-7239

Published May 24, 2010

The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 cert…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2011

Published May 21, 2010

Microsoft Dynamics GP uses a substitution cipher to encrypt the system password field and unspecified other fields, which makes it easier for remote authenticated users to obtain…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,301-2,325 of 2,510 CVEsPage 93 of 101