CWE-327
High likelihoodUse of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
671 vulnerabilities with CWE-327
CVE-2019-5754
MEDIUM
Google Chrome < 72.0.3626.81 - Cleartext Exposure via QUIC Networking Proxy
CVSS 6.5
CVE-2019-7673
HIGH
MOBOTIX S14 <MX-V4.2.1.61 - Info Disclosure
CVSS 7.5
CVE-2019-3818
HIGH
kube-rbac-proxy < 0.4.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2019-0030
HIGH
Juniper ATP <5.0.3 - Info Disclosure
CVSS 7.2
CVE-2019-5719
MEDIUM
Wireshark 2.4.0-2.4.11 and 2.6.0-2.6.5 - Denial of Service in ISAKMP Dissector
CVSS 5.5
CVE-2018-6402
HIGH
Ecobee Ecobee4 4.2.0.171 - Use of a Broken or Risky Cryptographic Algorithm via Evil Twin Attack
CVSS 7.5
CVE-2018-21058
CRITICAL
Android N(7.0) O(8.0) - Use of a Broken or Risky Cryptographic Algorithm in Keymaster AES-GCM
CVSS 9.8
CVE-2018-5745
MEDIUM
BIND <9.10.8-P1, <9.11.5-P1, <9.12.3-P1 - DoS
CVSS 4.9
CVE-2018-18371
MEDIUM
Broadcom Advanced Secure Gateway and ProxySG - Information Disclosure via WebFTP Mode
CVSS 6.5
CVE-2018-1720
MEDIUM
IBM Sterling B2B Integrator 5.2.0.1, 5.2.6.3_6, 6.0.0.0, 6.0.0.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2018-1996
MEDIUM
IBM WebSphere Application Server <9.0 - Info Disclosure
CVSS 5.3
CVE-2018-7959
MEDIUM
Huawei eSpace 7950 Firmware - Unauthenticated Sensitive Information Disclosure via Short Key Vulnerability
CVSS 5.9
CVE-2018-0734
MEDIUM
OpenSSL 1.0.2-1.0.2p 1.1.0-1.1.0i 1.1.1 - Timing Side Channel Attack via DSA Signature Algorithm
CVSS 5.9
CVE-2018-0735
MEDIUM
OpenSSL 1.1.0-1.1.0i and 1.1.1 - Timing Side Channel Attack in ECDSA Signature Algorithm
CVSS 5.9
CVE-2018-18587
MEDIUM
BigProf AppGini 5.70 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.3
CVE-2018-11070
MEDIUM
RSA BSAFE Crypto-J and SSL-J < 6.2.4 - Covert Timing Channel during PKCS #1 Unpadding
CVSS 5.9
CVE-2018-11069
MEDIUM
RSA BSAFE SSL-J < 6.2.4 - Covert Timing Channel during RSA Decryption
CVSS 5.9
CVE-2018-16806
MEDIUM
Pektron Passive Keyless Entry and Start System Firmware - Use of a Broken Cryptographic Algorithm via DST40 Cipher
CVSS 6.5
CVE-2018-11057
MEDIUM
RSA BSAFE Micro Edition Suite < 4.0.11 and < 4.1.6.1 - Covert Timing Channel during RSA Decryption
CVSS 5.9
CVE-2018-7792
HIGH
Schneider Electric Modicon M221 - Privilege Escalation
CVSS 7.5
CVE-2018-10846
MEDIUM
GnuTLS < 3.6.12 - Plain Text Recovery via Cache-Based Side Channel
CVSS 5.6
CVE-2018-10845
MEDIUM
GnuTLS < 3.6.12 - Timing Side-Channel Attack via HMAC-SHA-384
CVSS 5.9
CVE-2018-10844
MEDIUM
GnuTLS < 3.6.12 - Timing Side-Channel Attack via HMAC-SHA-256
CVSS 5.9
CVE-2018-15355
MEDIUM
Kraftway 24F2XG Router <3.5.30.1118 - Info Disclosure
CVSS 5.9
CVE-2018-12420
HIGH
IceHrm <23.0.1.OS - Info Disclosure
CVSS 7.5
Details
Vulnerabilities
671
Exploit Likelihood
High