CWE-326

Inadequate Encryption Strength

Parent: CWE-693 - Protection Mechanism Failure

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

457 vulnerabilities with CWE-326
CVE-2014-2381
Schneider Electric Wonderware Information Server - Info Disclosure
CVE-2014-2380
Schneider Electric Wonderware Information Server - Info Disclosure
CVE-2014-0224 HIGH
SSL Labs API Client
CVSS 7.4
CVE-2014-1491
Mozilla Network Security Services < 3.15.4 - Inadequate Encryption Strength in Diffie-Hellman Key Exchange
CVE-2013-7287 CRITICAL
MobileIron VSP <5.9.1 and Sentry <5.0 - Info Disclosure
CVSS 9.8
CVE-2013-7286 HIGH
MobileIron VSP < 5.9.1 - Info Disclosure
CVSS 7.5
CVE-2013-2166 CRITICAL
python-keystoneclient 0.2.3-0.2.5 - Inadequate Encryption Strength in Memcache Middleware
CVSS 9.8
CVE-2013-7484 HIGH
Zabbix < 5.0 - Inadequate Encryption Strength for User Passwords
CVSS 7.5
CVE-2013-4104 HIGH
Cryptocat < 2.0.22 - Inadequate Encryption Strength in Socialist Millionnaire Protocol
CVSS 7.5
CVE-2013-7469 HIGH
Seafile < 6.2.11 - Inadequate Encryption Strength via Static IV in CBC Mode
CVSS 7.5
CVE-2013-4508 HIGH
lighttpd 1.4.24-1.4.33 - Inadequate Encryption Strength in SNI Configuration
CVSS 7.5
CVE-2013-2566 MEDIUM
Oracle Communications Application Session Controller 3.0.0-3.9.1 - Inadequate Encryption Strength via RC4 Algorithm
CVSS 5.9
CVE-2013-0764
Firefox < 18.0 - Remote Code Execution via Thread-Unsafe SSL Session Handling
CVE-2012-2130 HIGH
PolarSSL 0.99pre4-1.1.1 - Inadequate Encryption Strength in Key Generation
CVSS 7.4
CVE-2012-6707 HIGH
WordPress < 4.8.2 - Inadequate Encryption Strength via MD5 Password Hashing
CVSS 7.5
CVE-2011-3629 HIGH
Joomla! core 1.7.1 - Info Disclosure
CVSS 7.5
CVE-2011-4121 CRITICAL
Ruby >=1.8.7.334 <1.9.3 - Inadequate Encryption Strength in OpenSSL RSA Key Generation
CVSS 9.8
CVE-2011-3389
SSL - Info Disclosure
CVE-2010-3670 MEDIUM
TYPO3 < 4.3.4 and 4.4.x < 4.4.1 - Insecure Randomness in Password Reset Hash Generation
CVSS 4.8
CVE-2009-2474
neon < 0.28.6 - SSL Certificate Validation Bypass via Null Byte in CN Field
CVE-2005-4900 MEDIUM
Google Chrome < 47.0.2526.111 - Inadequate Encryption Strength via SHA-1 Collision
CVSS 5.9
CVE-2005-2281 HIGH
WebEOC < 6.0.2 - Inadequate Encryption Strength for Passwords
CVSS 7.5
CVE-2005-0366
GnuPG < 1.4.1 - Plaintext Recovery via Chosen-Ciphertext Attack on CFB Mode
CVE-2004-2172 HIGH
EarlyImpact ProductCart - Info Disclosure
CVSS 7.5
CVE-2002-1682 MEDIUM
NewsReactor 1.0 - Inadequate Encryption Strength
CVSS 5.5
Details
Vulnerabilities 457