Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2014-4010

Published Jun 9, 2014

SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4008

Published Jun 9, 2014

SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4007

Published Jun 9, 2014

The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4005

Published Jun 9, 2014

SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4004

Published Jun 9, 2014

The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote attackers to obtain access via…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6223

Published Jun 9, 2014

LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to obtain access by reading the file.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2562

Published Jun 9, 2014

Mambo CMS 4.6.5 stores the MySQL database password in cleartext in the document root, which allows local users to obtain sensitive information via unspecified vectors.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2354

Published May 30, 2014

Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force atta…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0202

Published May 30, 2014

The setup script in ovirt-engine-dwh, as used in the Red Hat Enterprise Virtualization Manager data warehouse (rhevm-dwh) package before 3.3.3, stores the history database passwor…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0246

Published May 29, 2014

SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2350

Published May 22, 2014

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP se…

CVSS 2.4 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7382

Published May 17, 2014

VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for r…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1849

Published May 14, 2014

Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attacke…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6372

Published May 8, 2014

The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.c…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3220

Published May 5, 2014

F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-7134

Published Apr 29, 2014

Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4285

Published Apr 28, 2014

A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local users to obtain sensitive information by reading system memory.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2014

Published Apr 18, 2014

imapsync before 1.584, when running with the --tls option, attempts a cleartext login when a certificate verification failure occurs, which allows remote attackers to obtain crede…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0085

Published Apr 17, 2014

JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this d…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-2870

Published Apr 15, 2014

The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it easier for context-depe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 780 CVEsPage 14 of 32