← Back
CWE-327

685 CVEs • Abstraction: Class • Likelihood of Exploit: High

Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

JSON object

Loading...

CVEs (685)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Visionsoft
1Audit
Apr 23, 2026
Aug 3, 2007
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain sensitive information by sniffing the netw...Show more
The Visionsoft Audit on Demand Service (VSAOD) in Visionsoft Audit 12.4.0.0 uses weak cryptography (XOR) when (1) transmitting passwords, which allows remote attackers to obtain sensitive information by sniffing the network; and (2) storing passwords in the configuration file, which allows local users to obtain sensitive information by reading this file.Show less
1Spectrumcu
1Cash Receipting System
Apr 16, 2026
Dec 31, 2005
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Spectrum Cash Receipting System before 6.504 uses weak cryptography (static substitution) in the PASSFILE password file, which makes it easier for local users to gain privileges by decrypting a password.
2Canonical
Openssl
2Openssl
Ubuntu Linux
Apr 16, 2026
Sep 16, 2005
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid...Show more
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.Show less
1Teekai
1Tracking Online
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
5C2net
HpMicrosoft+2 more
13Certificate Server
Collabra ServerDirectory Server+10 more
Apr 16, 2026
Jun 26, 1998
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Information from SSL-encrypted sessions via PKCS #1.