CWE-326
455 CVEs • Abstraction: Class
Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
CVEs (455)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FujitsuMozilla+1 more16Communications Application Session Controller FirefoxHttp Server+13 moreApr 29, 2026 Mar 15, 2013 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a l...Show more |
4Canonical MozillaOpensuse+1 more9Firefox Linux Enterprise DesktopLinux Enterprise Server+6 moreApr 29, 2026 Jan 13, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thre...Show more |
9Canonical DebianGoogle+6 more15Chrome CurlDebian Linux+12 moreApr 29, 2026 Sep 6, 2011 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initializa...Show more |
4Apple CanonicalFedoraproject+1 more4Fedora Mac Os XNeon+1 moreApr 23, 2026 Aug 21, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...Show more |
WebEOC before 6.0.2 uses a weak encryption scheme for passwords, which makes it easier for attackers to crack passwords. |
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first...Show more |
1Netsourcecommerce 1Productcart Apr 16, 2026 Dec 31, 2004 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the password via a chosen plaintext attack. |
1Sharp 2Zaurus Sl 5000d Firmware Zaurus Sl 5500 FirmwareApr 16, 2026 Dec 31, 2002 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Sharp Zaurus PDA SL-5000D and SL-5500 uses a salt of "A0" to encrypt the screen-locking password as stored in the Security.conf file, which makes it easier for local users to guess the password via brute force methods. |
Videsh Sanchar Nigam Limited (VSNL) Integrated Dialer Software 1.2.000, when the "Save Password" option is used, stores the password with a weak encryption scheme (one-to-one mapping) in a registry key, which allows loca...Show more |
1Click 2 1Ingenium Learning Management System Apr 16, 2026 Dec 31, 2002 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), which allows attackers to obtain passwords. |
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. |
Alt-N Technologies Mdaemon 5.0 through 5.0.6 uses a weak encryption algorithm to store user passwords, which allows local users to crack passwords. |
Electronic Code Book (ECB) mode in VTun 2.0 through 2.5 uses a weak encryption algorithm that produces the same ciphertext from the same plaintext blocks, which could allow remote attackers to gain sensitive information. |
NewsReactor 1.0 uses a weak encryption scheme, which could allow local users to decrypt the passwords and gain access to other users' newsgroup accounts. |
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file. |