Vulnerabilities > Key Management Errors

DATE CVE VULNERABILITY TITLE RISK
2019-09-05 CVE-2019-14222 Key Management Errors vulnerability in Alfresco
An issue was discovered in Alfresco Community Edition versions 6.0 and lower.
network
low complexity
alfresco CWE-320
7.5
2019-07-29 CVE-2019-1020004 Key Management Errors vulnerability in Tridactyl Project Tridactyl 1.14.10/1.15.0
Tridactyl before 1.16.0 allows fake key events.
network
low complexity
tridactyl-project CWE-320
5.0
2019-07-09 CVE-2019-9150 Key Management Errors vulnerability in Mailvelope
Mailvelope prior to 3.3.0 does not require user interaction to import public keys shown on web page.
network
low complexity
mailvelope CWE-320
5.0
2019-05-23 CVE-2019-10851 Key Management Errors vulnerability in Computrols Building Automation Software
Computrols CBAS 18.0.0 has hard-coded encryption keys.
network
low complexity
computrols CWE-320
4.0
2019-05-16 CVE-2019-10112 Key Management Errors vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2.
network
low complexity
gitlab CWE-320
5.0
2019-04-22 CVE-2015-1316 Key Management Errors vulnerability in Canonical Juju
Juju Core's Joyent provider before version 1.25.5 uploads the user's private ssh key.
network
low complexity
canonical CWE-320
5.0
2019-04-17 CVE-2019-10643 Key Management Errors vulnerability in Contao CMS 4.7.0
Contao 4.7 allows Use of a Key Past its Expiration Date.
network
low complexity
contao CWE-320
7.5
2019-04-11 CVE-2019-5672 Key Management Errors vulnerability in Nvidia Jetson TX1 and Jetson TX2
NVIDIA Jetson TX1 and TX2 contain a vulnerability in the Linux for Tegra (L4T) operating system (on all versions prior to R28.3) where the Secure Shell (SSH) keys provided in the sample rootfs are not replaced by unique host keys after sample rootsfs generation and flashing, which may lead to information disclosure.
network
low complexity
nvidia CWE-320
6.4
2019-03-21 CVE-2019-9894 Key Management Errors vulnerability in multiple products
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
network
low complexity
putty fedoraproject debian netapp opensuse CWE-320
7.5
2019-03-08 CVE-2018-20187 Key Management Errors vulnerability in Botan Project Botan
A side-channel issue was discovered in Botan before 2.9.0.
4.3