VulnSea

CWE-327

CVEs classified under CWE-327, newest first.

39 CVEsRSS

CVE-2026-5682Low· 3.7PoC
5mo ago

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android

A vulnerability has been found in Meesho Online Shopping App up to 27.3 on Android. Affected is an unknown function of the file /api/endpoint of the component com.meesho.supply. Such manipulation leads to risky cryptographic algorithm. T…

▾ TwilightEPSS 0.28%via NVD
CVE-2024-22347Medium· 5.9
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

▾ Sunlithcltech · devops_velocityEPSS 0.33%via NVD
CVE-2023-46233Critical· 9.1
2y ago

crypto-js is a JavaScript library of crypto standards

crypto-js is a JavaScript library of crypto standards. Prior to version 4.2.0, crypto-js PBKDF2 is 1,000 times weaker than originally specified in 1993, and at least 1,300,000 times weaker than current industry standard. This is because …

▾ Midnightcrypto-js_project · crypto-jsEPSS 0.64%via NVD
CVE-2021-45485High· 7.5PoC
4y ago

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically ch…

▾ Midnightnetapp · e-series_santricity_os_controllerEPSS 3.6%via NVD
CVE-2021-2351High· 8.3
5y ago

Vulnerability in the Advanced Networking Option component of Oracle Database Server

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network acc…

▾ Twilightoracle · advanced_networking_optionEPSS 2.4%via NVD
CVE-2020-25493High· 7.5
5y ago

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic

Oclean Mobile Application 2.1.2 communicates with an external website using HTTP so it is possible to eavesdrop the network traffic. The content of HTTP payload is encrypted using XOR with a hardcoded key, which allows for the possibilit…

▾ Twilightoclean · ocleanEPSS 0.89%via NVD
CVE-2020-20949Medium· 5.9
5y ago

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924)

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciph…

▾ Sunlitst · stm32cubef0EPSS 0.93%via NVD
CVE-2020-20950Medium· 5.9
5y ago

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by …

▾ Sunlitietf · public_key_cryptography_standards_#1EPSS 0.87%via NVD
CVE-2018-5745Medium· 4.9
6y ago

"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation

"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation. Due to an error in the managed-keys feature it is possible for a BI…

▾ Sunlitisc · bindEPSS 2.3%via NVD
CWE-327 vulnerabilities (CVEs) — page 2 · VulnSea