Skip to main content

CWE archive

CWE-327 CVEs

Programmatic archive

685 CVEs tagged with CWE-32765 Critical, 256 High, 300 Medium, 64 Low, 0 Unrated.

CVE-2021-37588

Published Jul 30, 2021

In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37587

Published Jul 30, 2021

In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-20497

Published Jul 15, 2021

IBM Security Verify Access Docker 10.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34687

Published Jul 15, 2021

iDrive RemotePC before 7.6.48 on Windows allows information disclosure. A man in the middle can recover a system's Personal Key when a client attempts to make a LAN connection. Th…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29794

Published Jul 12, 2021

IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expected cryptographic algorithms that could allow an attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20379

Published Jul 7, 2021

IBM Guardium Data Encryption (GDE) 3.0.0.3 and 4.0.0.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22212

Published Jun 8, 2021

ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-26515

Published Jun 8, 2021

An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The remember-me cookie (CB_LOGIN) issued by the application contains…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27457

Published May 20, 2021

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive…

CVSS 7.5 · High

CVE-2020-36315

Published Apr 7, 2021

In RELIC before 2020-08-01, RSA PKCS#1 v1.5 signature forgery can occur because certain checks of the padding (and of the first two bytes) are inadequate. NOTE: this requires that…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14852

Published Mar 18, 2021

A flaw was found in 3scale’s APIcast gateway that enabled the TLS 1.0 protocol. An attacker could target traffic using this weaker protocol and break its encryption, gaining acces…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-4831

Published Mar 12, 2021

IBM DataPower Gateway 10.0.0.0 through 10.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Forc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 426-450 of 685 CVEsPage 18 of 28