Vulnerabilities > Key Management Errors

DATE CVE VULNERABILITY TITLE RISK
2019-01-11 CVE-2017-13887 Key Management Errors vulnerability in Apple mac OS X
In macOS High Sierra before 10.13.2, a logic issue existed in APFS when deleting keys during hibernation.
network
low complexity
apple CWE-320
5.0
2019-01-03 CVE-2017-18323 Key Management Errors vulnerability in Qualcomm products
Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130.
local
low complexity
qualcomm CWE-320
2.1
2019-01-03 CVE-2017-18319 Key Management Errors vulnerability in Qualcomm products
Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016.
local
low complexity
qualcomm CWE-320
2.1
2018-07-31 CVE-2016-8614 Key Management Errors vulnerability in Redhat Ansible
A flaw was found in Ansible before version 2.2.0.
network
low complexity
redhat CWE-320
7.5
2018-06-15 CVE-2018-12433 Key Management Errors vulnerability in Cryptlib 3.4.4
cryptlib through 3.4.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
high complexity
cryptlib CWE-320
4.9
2018-06-13 CVE-2018-7559 Key Management Errors vulnerability in Opcfoundation Ua-.Net-Legacy and Ua-.Netstandard
An issue was discovered in OPC UA .NET Standard Stack and Sample Code before GitHub commit 2018-04-12, and OPC UA .NET Legacy Stack and Sample Code before GitHub commit 2018-03-13.
3.5
2018-06-12 CVE-2018-0732 Key Management Errors vulnerability in multiple products
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client.
network
low complexity
openssl debian canonical nodejs CWE-320
7.5
2018-06-04 CVE-2016-1000346 Key Management Errors vulnerability in multiple products
In the Bouncy Castle JCE Provider version 1.55 and earlier the other party DH public key is not fully validated.
4.3
2018-05-30 CVE-2018-7534 Key Management Errors vulnerability in Unisys Stealth Authorization Server
In Stealth Authorization Server before 3.3.017.0 in Unisys Stealth Solution, an encryption key may be left in memory.
local
unisys CWE-320
1.9
2018-05-04 CVE-2013-2233 Key Management Errors vulnerability in Redhat Ansible
Ansible before 1.2.1 makes it easier for remote attackers to conduct man-in-the-middle attacks by leveraging failure to cache SSH host keys.
network
redhat CWE-320
5.8