CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

448 vulnerabilities with CWE-326
CVE-2013-7469 HIGH
Seafile < 6.2.11 - Inadequate Encryption Strength via Static IV in CBC Mode
CVSS 7.5
CVE-2013-4508 HIGH
lighttpd 1.4.24-1.4.33 - Inadequate Encryption Strength in SNI Configuration
CVSS 7.5
CVE-2013-2566 MEDIUM
Oracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm
CVSS 5.9
CVE-2013-0764
Firefox < 18.0 - Remote Code Execution via Thread-Unsafe SSL Session Handling
CVE-2012-2130 HIGH
PolarSSL 0.99pre4-1.1.1 - Inadequate Encryption Strength in Key Generation
CVSS 7.4
CVE-2012-6707 HIGH
WordPress < 4.8.2 - Inadequate Encryption Strength via MD5 Password Hashing
CVSS 7.5
CVE-2011-3629 HIGH
Joomla! core 1.7.1 - Info Disclosure
CVSS 7.5
CVE-2011-4121 CRITICAL
Ruby >=1.8.7.334 <1.9.3 - Inadequate Encryption Strength in OpenSSL RSA Key Generation
CVSS 9.8
CVE-2011-3389
SSL - Info Disclosure
CVE-2010-3670 MEDIUM
TYPO3 < 4.3.4 and 4.4.x < 4.4.1 - Insecure Randomness in Password Reset Hash Generation
CVSS 4.8
CVE-2009-2474
neon < 0.28.6 - SSL Certificate Validation Bypass via Null Byte in CN Field
CVE-2005-4900 MEDIUM
Google Chrome < 47.0.2526.111 - Inadequate Encryption Strength via SHA-1 Collision
CVSS 5.9
CVE-2005-2281 HIGH
WebEOC < 6.0.2 - Inadequate Encryption Strength for Passwords
CVSS 7.5
CVE-2005-0366
GnuPG < 1.4.1 - Plaintext Recovery via Chosen-Ciphertext Attack on CFB Mode
CVE-2004-2172 HIGH
EarlyImpact ProductCart - Info Disclosure
CVSS 7.5
CVE-2002-1682 MEDIUM
NewsReactor 1.0 - Inadequate Encryption Strength
CVSS 5.5
CVE-2002-1697 HIGH
VTun 2.0-2.5 - Inadequate Encryption Strength via ECB Mode
CVSS 7.5
CVE-2002-1739 MEDIUM
Mdaemon 5.0-5.0.6 - Inadequate Encryption Strength for User Passwords
CVSS 5.5
CVE-2002-1872 HIGH
Microsoft SQL Server 6.0-2000 - Weak Password Encryption via XOR
CVSS 7.5
CVE-2002-1910 HIGH
Click2Learn Ingenium Learning Management System 5.1 and 6.1 - Inadequate Encryption Strength
CVSS 7.5
CVE-2002-1946 MEDIUM
Videsh Sanchar Nigam Limited Integrated Dialer 1.2.000 - Inadequate Encryption Strength in Saved Password
CVSS 5.5
CVE-2002-1975 MEDIUM
Sharp Zaurus SL-5000D and SL-5500 Firmware - Inadequate Encryption Strength in Password Storage
CVSS 5.5
CVE-2001-1546 HIGH
Pathways Homecare 6.5 - Info Disclosure
CVSS 7.8
Details
Vulnerabilities 448