CWE-327

High likelihood

Use of a Broken or Risky Cryptographic Algorithm

Parent: CWE-693 - Protection Mechanism Failure

The product uses a broken or risky cryptographic algorithm or protocol.

671 vulnerabilities with CWE-327
CVE-2018-5152 MEDIUM
Firefox < 60.0 - WebExtension Content Script Network Traffic Interception
CVSS 6.5
CVE-2018-1000180 HIGH
Bouncy Castle <1.60-1.59 - Info Disclosure
CVSS 7.5
CVE-2018-11209 HIGH
Z-BlogPHP 2.0.0 - Use of a Broken or Risky Cryptographic Algorithm in Password Verification
CVSS 7.2
CVE-2018-6619 HIGH
Easy Hosting Control Panel 0.37.12.b - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.8
CVE-2018-10831 HIGH
z-nomp < 1.0.5 - Incorrect Equihash Solution Verification
CVSS 7.5
CVE-2018-0737 MEDIUM
OpenSSL 1.0.2b-1.0.2o and 1.1.0-1.1.0h - Private Key Recovery via Cache Timing Side Channel
CVSS 5.9
CVE-2018-5382 MEDIUM
Bouncy Castle <1.47 - Integrity Compromise
CVSS 4.4
CVE-2018-10084 HIGH
CMSMS <2.2.6 - Privilege Escalation
CVSS 8.8
CVE-2018-5458 HIGH
Philips IntelliSpace Portal - Info Disclosure
CVSS 7.5
CVE-2018-1428 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 6.2
CVE-2018-7211 HIGH
iDashboards < 9.6b - Weak Obfuscation in SSO Implementation
CVSS 8.1
CVE-2018-6829 HIGH
Libgcrypt < 1.8.2 - Information Disclosure via ElGamal Ciphertext-Only Attack
CVSS 7.5
CVE-2017-2488 HIGH
Apple Remote Desktop < 3.9 - Cleartext Password Exposure via Weak Authentication Protocol
CVSS 7.5
CVE-2017-1575 MEDIUM
IBM Sterling File Gateway 2.2.0-2.2.6 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.1
CVE-2017-16718 MEDIUM
Beckhoff TwinCAT 3 - Info Disclosure
CVSS 5.9
CVE-2017-12129 HIGH
Moxa EDR-810 V4.1 - Info Disclosure
CVSS 8.0
CVE-2017-15326 MEDIUM
DBS3900 TDD LTE V100R003C00, V100R004C10 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 4.3
CVE-2017-1571 MEDIUM
IBM DB2 9.7, 10.1, 10.5, 11.1 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.1
CVE-2017-17167 MEDIUM
Huawei DP300 V500R002C00; TP3206 V100R002C00; ViewPoint 9030 V100R011C02/C03 - Broken Cryptographic Algorithm in SSL
CVSS 5.9
CVE-2017-17428 MEDIUM
Cavium Nitrox SSL SDK < 6.1.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 5.9
CVE-2017-17878 CRITICAL
Valve Steam Link Firmware < 644 - Weak Password Hashing via DES Truncation
CVSS 9.8
CVE-2017-1598 HIGH
IBM Security Guardium 10.0 - Use of a Broken or Risky Cryptographic Algorithm
CVSS 7.5
CVE-2017-17717 CRITICAL
Sonatype Nexus Repository Manager < 2.14.5 - Weak Password Encryption in LDAP Integration
CVSS 9.8
CVE-2017-17382 MEDIUM
Citrix NetScaler <10.5.67.13-12.0.53.22 - RCE
CVSS 5.9
CVE-2017-8866 MEDIUM
CogniToys Dino Firmware < 0.0.794 - Remote VoIP Traffic Decryption via Hardcoded Keys
CVSS 5.9
Details
Vulnerabilities 671
Exploit Likelihood High