Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2014-9251

Published Dec 15, 2014

Zenoss Core through 5 Beta 3 uses a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack on…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-9248

Published Dec 15, 2014

Zenoss Core through 5 Beta 3 does not require complex passwords, which makes it easier for remote attackers to obtain access via a brute-force attack, aka ZEN-15406.

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-9183

Published Dec 2, 2014

ZTE ZXDSL 831CII has a default password of admin for the admin account, which allows remote attackers to gain administrator privileges.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3068

Published Dec 2, 2014

IBM Java Runtime Environment (JRE) 7 R1 before SR1 FP1 (7.1.1.1), 7 before SR7 FP1 (7.0.7.1), 6 R1 before SR8 FP1 (6.1.8.1), 6 before SR16 FP1 (6.0.16.1), and before 5.0 SR16 FP7…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9152

Published Dec 1, 2014

The _user_resource_create function in the Services module 7.x-3.x before 7.x-3.10 for Drupal uses a password of 1 when creating new user accounts, which makes it easier for remote…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-7845

Published Nov 24, 2014

The generate_password function in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 does not provide a sufficient number of possible temporary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9006

Published Nov 20, 2014

Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the lo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6098

Published Nov 18, 2014

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 allows remote attackers to discover cleartext passwords via a crafted request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7823

Published Nov 13, 2014

The virDomainGetXMLDesc API in Libvirt before 1.2.11 allows remote read-only users to obtain the VNC password by using the VIR_DOMAIN_XML_MIGRATABLE flag, which triggers the use o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8527

Published Oct 29, 2014

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows local users to obtain sensitive information and affect integrity via vectors related to a "plain text password."

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6099

Published Oct 26, 2014

The Change Password feature in IBM Sterling B2B Integrator 5.2.x through 5.2.4 does not have a lockout protection mechanism for invalid login requests, which makes it easier for r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4450

Published Oct 22, 2014

The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5423

Published Oct 19, 2014

CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 allows local users to obtain potentially sensitive information by reading a temporary (1) debugging file o…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5422

Published Oct 19, 2014

CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded service password, which makes it easier for remote attackers to obtain access via unspecif…

CVSS 9.7 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-5421

Published Oct 19, 2014

CareFusion Pyxis SupplyStation 8.1 with hardware test tool 1.0.16 and earlier has a hardcoded database password, which makes it easier for local users to gain privileges by levera…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5420

Published Oct 19, 2014

CareFusion Pyxis SupplyStation 8.1 with hardware test tool before 1.0.16 has a hardcoded application password, which makes it easier for remote authenticated users to obtain appli…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-5351

Published Oct 10, 2014

The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) before 1.13 sends old keys in a response to a -randkey -keepold req…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-6607

Published Oct 6, 2014

M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the password of other users and gain privileges…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-2942

Published Sep 22, 2014

Cobham Aviator 700D and 700E satellite terminals use an improper algorithm for PIN codes, which makes it easier for attackers to obtain a privileged terminal session by calculatin…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4366

Published Sep 18, 2014

Mail in Apple iOS before 8 does not prevent sending a LOGIN command to a LOGINDISABLED IMAP server, which allows remote attackers to obtain sensitive cleartext information by snif…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 780 CVEsPage 12 of 32