Secure Elements Class 5 AVR (aka C5 EVM) client and server before 2.8.1 do not verify the integrity of a message digest, which allows remote attackers to modify and replay messages.
https://exchange.xforce.ibmcloud.com/vulnerabilities/26781
https://exchange.xforce.ibmcloud.com/vulnerabilities/26765
http://www.vupen.com/english/advisories/2006/2069
http://www.kb.cert.org/vuls/id/WDON-6QAQFH
http://www.kb.cert.org/vuls/id/WDON-6Q6S8D
http://www.kb.cert.org/vuls/id/456729
http://www.kb.cert.org/vuls/id/353769