CVE-2004-2761
9.8 CRITICALThe MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing at...
Published: 2009-01-05 · Last updated: 2026-05-28
Severity and scoring
- CVSS
- 9.8 CRITICAL
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-310, CWE-328
Affected products
| Vendor | Product |
|---|---|
| ietf | md5 |
Description
The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2004-2761
- [Other]http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/
- [Other]http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx
- [Other]http://secunia.com/advisories/33826
- [Other]http://secunia.com/advisories/34281
- [Other]http://secunia.com/advisories/42181
- [Other]http://securityreason.com/securityalert/4866
- [Other]http://securitytracker.com/id?1024697
- [Other]http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html
- [Other]http://www.doxpara.com/research/md5/md5_someday.pdf
- [Other]http://www.kb.cert.org/vuls/id/836068
- [Patch]http://www.microsoft.com/technet/security/advisory/961509.mspx
- [Other]http://www.phreedom.org/research/rogue-ca/
- [Other]http://www.securityfocus.com/archive/1/499685/100/0/threaded
- [Other]http://www.securityfocus.com/bid/33065
- [Other]http://www.ubuntu.com/usn/usn-740-1
- [Other]http://www.win.tue.nl/hashclash/SoftIntCodeSign/
- [Other]http://www.win.tue.nl/hashclash/rogue-ca/
- [Other]https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=648886
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888
- [Other]https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- [Other]https://rhn.redhat.com/errata/RHSA-2010-0837.html
- [Other]https://rhn.redhat.com/errata/RHSA-2010-0838.html
- [Other]https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html
- [Other]http://blog.mozilla.com/security/2008/12/30/md5-weaknesses-could-lead-to-certificate-forgery/
- [Other]http://blogs.technet.com/swi/archive/2008/12/30/information-regarding-md5-collisions-problem.aspx
- [Other]http://secunia.com/advisories/33826
- [Other]http://secunia.com/advisories/34281
- [Other]http://secunia.com/advisories/42181
- [Other]http://securityreason.com/securityalert/4866
- [Other]http://securitytracker.com/id?1024697
- [Other]http://www.cisco.com/en/US/products/products_security_response09186a0080a5d24a.html
- [Other]http://www.doxpara.com/research/md5/md5_someday.pdf
- [Other]http://www.kb.cert.org/vuls/id/836068
- [Patch]http://www.microsoft.com/technet/security/advisory/961509.mspx
- [Other]http://www.phreedom.org/research/rogue-ca/
- [Other]http://www.securityfocus.com/archive/1/499685/100/0/threaded
- [Other]http://www.securityfocus.com/bid/33065
- [Other]http://www.ubuntu.com/usn/usn-740-1
- [Other]http://www.win.tue.nl/hashclash/SoftIntCodeSign/
- [Other]http://www.win.tue.nl/hashclash/rogue-ca/
- [Other]https://blogs.verisign.com/ssl-blog/2008/12/on_md5_vulnerabilities_and_mit.php
- [Other]https://bugzilla.redhat.com/show_bug.cgi?id=648886
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289935
- [Other]https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05336888
- [Other]https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02
- [Other]https://rhn.redhat.com/errata/RHSA-2010-0837.html
- [Other]https://rhn.redhat.com/errata/RHSA-2010-0838.html
- [Other]https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03814en_us
- [Other]https://www.redhat.com/archives/fedora-package-announce/2009-February/msg00096.html
Related CVEs
Same CWE
- CVE-2026-48488 — phpMyFAQ is an open source FAQ web application
- CVE-2026-11481 — A vulnerability was determined in yoanbernabeu grepai up to 0.35.0 (2.5 LOW)
- CVE-2026-11479 — A vulnerability has been found in yoanbernabeu grepai 0.35.0 (4.2 MEDIUM)
- CVE-2026-11330 — A weakness has been identified in thedotmack claude-mem up to 11.0.1 (3.6 LOW)
- CVE-2026-11329 — A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0 (3.6 LOW)