Vulnerabilities > Inadequate Encryption Strength

DATE CVE VULNERABILITY TITLE RISK
2019-12-06 CVE-2012-2130 Inadequate Encryption Strength vulnerability in multiple products
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
network
high complexity
polarssl debian fedoraproject CWE-326
7.4
2019-11-30 CVE-2013-7484 Inadequate Encryption Strength vulnerability in Zabbix 2.0.8/4.4.0
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
network
low complexity
zabbix CWE-326
7.5
2019-11-26 CVE-2011-4121 Inadequate Encryption Strength vulnerability in Ruby-Lang Ruby
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation.
network
low complexity
ruby-lang CWE-326
critical
9.8
2019-11-26 CVE-2019-18241 Inadequate Encryption Strength vulnerability in Philips products
In Philips IntelliBridge EC40 and EC80, IntelliBridge EC40 Hub all versions, and IntelliBridge EC80 Hub all versions, the SSH server running on the affected products is configured to allow weak ciphers.
low complexity
philips CWE-326
6.5
2019-11-08 CVE-2019-13539 Inadequate Encryption Strength vulnerability in Medtronic products
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform (VLFT10GEN) software version 4.0.0 and below, and Valleylab FX8 Energy Platform (VLFX8GEN) software version 1.1.0 and below use the descrypt algorithm for OS password hashing.
local
low complexity
medtronic CWE-326
7.8
2019-11-05 CVE-2010-3670 Inadequate Encryption Strength vulnerability in Typo3
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
network
high complexity
typo3 CWE-326
4.8
2019-11-05 CVE-2019-17598 Inadequate Encryption Strength vulnerability in Lightbend Play Framework
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.
network
low complexity
lightbend CWE-326
7.5
2019-11-04 CVE-2013-4104 Inadequate Encryption Strength vulnerability in Cryptocat Project Cryptocat
Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol
network
low complexity
cryptocat-project CWE-326
7.5
2019-10-29 CVE-2019-4339 Inadequate Encryption Strength vulnerability in IBM Security Guardium BIG Data Intelligence 4.0
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5
2019-09-17 CVE-2019-4175 Inadequate Encryption Strength vulnerability in IBM Cognos Controller 10.4.0/10.4.1
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
network
low complexity
ibm CWE-326
7.5