Vulnerabilities (CVE)

Filtered by CWE-417
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-3969 1 Mcafee 1 Network Security Manager 2019-10-09 4.3 MEDIUM 5.9 MEDIUM
Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows man-in-the-middle attackers to decrypt messages via an inadequate implementation of SSL.
CVE-2019-14318 1 Cryptopp 1 Crypto\+\+ 2019-08-20 4.3 MEDIUM 5.9 MEDIUM
Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves, small leakage) and algebra.cpp (binary field curves, large leakage) is not constant time and leaks the bit length of the scalar among other information.
CVE-2017-2712 1 Huawei 2 S3300, S3300 Firmware 2017-12-08 5.0 MEDIUM 5.3 MEDIUM
S3300 V100R006C05 have an Ethernet in the First Mile (EFM) flapping vulnerability due to the lack of type-length-value (TLV) consistency check. An attacker may craft malformed packets and send them to a device to cause EFM flapping.