Show filters
146 Total Results
Displaying 121-130 of 146
Sort by:
Attacker Value
Unknown
CVE-2020-10866
Disclosure Date: April 01, 2020 (last updated February 21, 2025)
An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC.
0
Attacker Value
Unknown
CVE-2019-14855
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18.
0
Attacker Value
Unknown
CVE-2019-12121
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
An issue was detected in ONAP Portal through Dublin. By executing a padding oracle attack using the ONAPPORTAL/processSingleSignOn UserId field, an attacker is able to decrypt arbitrary information encrypted with the same symmetric key as UserId. All Portal setups are affected.
0
Attacker Value
Unknown
CVE-2019-19299
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0), SiNVR/SiVMS Video Server (All versions >= V5.0.0 < V5.0.2), SiNVR/SiVMS Video Server (All versions >= V5.0.2). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server
applies weak cryptography when exposing device (camera) passwords.
This could allow an unauthenticated remote attacker to read and decrypt
the passwords and conduct further attacks.
0
Attacker Value
Unknown
CVE-2020-10244
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
0
Attacker Value
Unknown
CVE-2020-9476
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
0
Attacker Value
Unknown
CVE-2019-18863
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
0
Attacker Value
Unknown
CVE-2019-4557
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
0
Attacker Value
Unknown
CVE-2013-7287
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
0
Attacker Value
Unknown
CVE-2013-7286
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
0