Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Mikel Olasagasti Subscribe
Filtered by product Revelation
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2012-2742 1 Mikel Olasagasti 1 Revelation 2017-08-28 5.0 MEDIUM N/A
Revelation 0.4.13-2 and earlier uses only the first 32 characters of a password followed by a sequence of zeros, which reduces the entropy and makes it easier for context-dependent attackers to crack passwords and obtain access to keys via a brute-force attack.
CVE-2012-2743 1 Mikel Olasagasti 1 Revelation 2017-08-28 5.0 MEDIUM N/A
Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easier for context-dependent attackers to guess passwords via a brute force attack.
CVE-2012-3818 1 Mikel Olasagasti 1 Revelation 2012-07-02 2.1 LOW N/A
The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.