Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2011-4678

Published Dec 6, 2011

The password reset feature in One Click Orgs before 1.2.3 generates different error messages for failed reset attempts depending on whether the e-mail address is registered, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4555

Published Dec 6, 2011

One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4965

Published Oct 16, 2011

/etc/rc.d/rc.local on the D-Link DCS-2121 camera with firmware 1.04 configures a hardcoded password of admin for the root account, which makes it easier for remote attackers to ob…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-3434

Published Oct 14, 2011

The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3429

Published Oct 14, 2011

The Settings component in Apple iOS before 5 stores a cleartext parental-restrictions passcode in an unspecified file, which might allow physically proximate attackers to obtain s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3255

Published Oct 14, 2011

CFNetwork in Apple iOS before 5 stores AppleID credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted applica…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3245

Published Oct 14, 2011

The Keyboards component in Apple iOS before 5 displays the final character of an entered password during a subsequent use of a keyboard, which allows physically proximate attacker…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2990

Published Aug 18, 2011

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1742

Published Aug 1, 2011

EMC Data Protection Advisor before 5.8.1 places cleartext account credentials in the DPA configuration file in unspecified circumstances, which might allow local users to obtain s…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-2024

Published Jun 2, 2011

Cisco Network Registrar before 7.2 has a default administrative password, which makes it easier for remote attackers to obtain access via a TCP session, aka Bug ID CSCsm50627.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1906

Published May 5, 2011

Trustwave WebDefend Enterprise before 5.0 7.01.903-1.4 stores specific user-account credentials in a MySQL database, which makes it easier for remote attackers to read the event c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0756

Published May 5, 2011

The application server in Trustwave WebDefend Enterprise before 5.0 uses hardcoded console credentials, which makes it easier for remote attackers to read security-event data by u…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1690

Published Apr 22, 2011

Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1822

Published Apr 21, 2011

The LDAP_ADD implementation in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0009 stores a cleartext SHA password in the change log, which might allow local user…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0412

Published Apr 19, 2011

Oracle Solaris 8, 9, and 10 stores back-out patch files (undo.Z) unencrypted with world-readable permissions under /var/sadm/pkg/, which allows local users to obtain password hash…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 526-550 of 780 CVEsPage 22 of 32