Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2014-4363

Published Sep 18, 2014

Safari in Apple iOS before 8 does not properly restrict the autofilling of passwords in forms, which allows remote attackers to obtain sensitive information via (1) an http web si…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4864

Published Sep 10, 2014

The NETGEAR ProSafe Plus Configuration Utility creates configuration backup files containing cleartext passwords, which might allow remote attackers to obtain sensitive informatio…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4788

Published Sep 10, 2014

IBM Initiate Master Data Service 9.5 before 9.5.093013, 9.7 before 9.7.093013, 10.0 before 10.0.093013, and 10.1 before 10.1.093013 does not have an off autocomplete attribute for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0863

Published Sep 5, 2014

The client in IBM Cognos TM1 9.5.2.3 before IF5, 10.1.1.2 before IF1, 10.2.0.2 before IF1, and 10.2.2.0 before IF1 stores obfuscated passwords in memory, which allows remote authe…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5504

Published Sep 4, 2014

SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5253

Published Aug 25, 2014

OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 does not properly revoke tokens when a domain is invalidated, which allows remote authenticated use…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5252

Published Aug 25, 2014

The V3 API in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 updates the issued_at value for UUID v2 tokens, which allows remote authenticated use…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-5251

Published Aug 25, 2014

The MySQL token driver in OpenStack Identity (Keystone) 2014.1.x before 2014.1.2.1 and Juno before Juno-3 stores timestamps with the incorrect precision, which causes the expirati…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3528

Published Aug 19, 2014

Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier…

CVSS 4.0 · Medium

CVE-2013-7395

Published Aug 12, 2014

ZOLL Defibrillator / Monitor X Series has a default (1) supervisor password and (2) service password, which allows physically proximate attackers to modify device configuration an…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-6756

Published Aug 12, 2014

ZOLL Defibrillator / Monitor M Series, E Series, and R Series have a default password for System Configuration mode, which allows physically proximate attackers to modify device c…

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-2226

Published Jul 29, 2014

Ubiquiti UniFi Controller before 3.2.1 logs the administrative password hash in syslog messages, which allows man-in-the-middle attackers to obtain sensitive information via unspe…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-4018

Published Jul 16, 2014

The ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via u…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5755

Published Jul 16, 2014

config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) v…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3419

Published Jul 15, 2014

Infoblox NetMRI before 6.8.5 has a default password of admin for the "root" MySQL database account, which makes it easier for local users to obtain access via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2014-3489

Published Jul 7, 2014

lib/util/miq-password.rb in Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 uses a hard-coded salt, which makes it easier for remote attackers to guess passwords vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0184

Published Jul 7, 2014

Red Hat CloudForms 3.0 Management Engine (CFME) before 5.2.4.2 logs the root password when deploying a VM, which allows local users to obtain sensitive information by reading the…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2969

Published Jul 7, 2014

NETGEAR GS108PE Prosafe Plus switches with firmware 1.2.0.5 have a hardcoded password of debugpassword for the ntgruser account, which allows remote attackers to upload firmware o…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-3298

Published Jul 2, 2014

Form Data Viewer in Cisco Intelligent Automation for Cloud in Cisco Cloud Portal places passwords in form data, which allows remote authenticated users to obtain sensitive informa…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4012

Published Jun 9, 2014

SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4011

Published Jun 9, 2014

SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 780 CVEsPage 13 of 32