Vulnerabilities > Key Management Errors

DATE CVE VULNERABILITY TITLE RISK
2019-07-09 CVE-2019-9150 Key Management Errors vulnerability in Mailvelope
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page.
network
low complexity
mailvelope CWE-320
5.3
2019-04-22 CVE-2015-1316 Key Management Errors vulnerability in Canonical Juju
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
network
low complexity
canonical CWE-320
7.5
2019-04-11 CVE-2019-5672 Key Management Errors vulnerability in Nvidia Jetson TX1 and Jetson TX2
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.
network
low complexity
nvidia CWE-320
critical
9.1
2019-03-21 CVE-2019-9894 Key Management Errors vulnerability in multiple products
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
network
low complexity
putty fedoraproject debian netapp opensuse CWE-320
7.5
2019-03-08 CVE-2018-20187 Key Management Errors vulnerability in Botan Project Botan
A side-channel issue was discovered in Botan before 2.9.0.
network
high complexity
botan-project CWE-320
5.9
2019-01-11 CVE-2017-13887 Key Management Errors vulnerability in Apple mac OS X
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
network
low complexity
apple CWE-320
7.5
2019-01-03 CVE-2017-18323 Key Management Errors vulnerability in Qualcomm products
Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130.
local
low complexity
qualcomm CWE-320
5.5
2019-01-03 CVE-2017-18319 Key Management Errors vulnerability in Qualcomm products
Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016.
local
low complexity
qualcomm CWE-320
5.5
2018-07-31 CVE-2016-8614 Key Management Errors vulnerability in Redhat Ansible
A flaw was found in Ansible before version 2.2.0.
network
low complexity
redhat CWE-320
7.5
2018-06-15 CVE-2018-12438 Key Management Errors vulnerability in Libsunec Project Libsunec
The Elliptic Curve Cryptography library (aka sunec or libsunec) allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
high complexity
libsunec-project CWE-320
4.9