Skip to main content

CWE archive

CWE-326 CVEs

Programmatic archive

459 CVEs tagged with CWE-32649 Critical, 191 High, 197 Medium, 22 Low, 0 Unrated.

CVE-2017-3971

Published Apr 4, 2018

Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to view confidential information via insecure use o…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4953

Published Mar 29, 2018

IBM BigFix Remote Control before Interim Fix pack 9.1.2-TIV-IBRC912-IF0001 makes it easier for man-in-the-middle attackers to decrypt traffic by leveraging a weakness in its encry…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7449

Published Mar 20, 2018

IBM Rational Collaborative Lifecycle Management (CLM) 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, 6.0.x before 6.0.1 iFix5, and 6.0.2 before iFix2; Rational Quality Mana…

CVSS 3.3 · Low

CVE-2018-6653

Published Mar 1, 2018

comforte SWAP 1049 through 1069 and 20.0.0 through 21.5.3 (as used in SSLOBJ on HPE NonStop SSL T0910, and in the comforte SecurCS, SecurFTP, SecurLib/SSL-AT, and SecurTN products…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1425

Published Feb 27, 2018

IBM Security Guardium Big Data Intelligence (SonarG) 3.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. I…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6635

Published Feb 5, 2018

System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-5298

Published Jan 8, 2018

In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1664

Published Jan 4, 2018

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-F…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-1000486

Published Jan 3, 2018

Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
36.9
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-14090

Published Dec 16, 2017

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1271

Published Dec 7, 2017

IBM Security Guardium 9.0, 9.1, and 9.5 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13699

Published Nov 23, 2017

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The password encryption method can be retrieved from the firmware. This encryption method is based on a chall…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1375

Published Oct 24, 2017

IBM System Storage Storwize V7000 Unified (V7000U) 1.5 and 1.6 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive informat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6707

Published Oct 19, 2017

WordPress through 4.8.2 uses a weak MD5-based password hashing algorithm, which makes it easier for attackers to determine cleartext values by leveraging access to the hash values…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 376-400 of 459 CVEsPage 16 of 19