Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2011-1560

Published Apr 5, 2011

solid.exe in IBM solidDB before 4.5.181, 6.0.x before 6.0.1067, 6.1.x and 6.3.x before 6.3.47, and 6.5.x before 6.5.0.3 uses a password-hash length specified by the client, which…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0951

Published Apr 4, 2011

The web-based management interface in Cisco Secure Access Control System (ACS) 5.1 before 5.1.0.44.6 and 5.2 before 5.2.0.26.3 allows remote attackers to change arbitrary user pas…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4764

Published Mar 18, 2011

Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG key…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1007

Published Feb 28, 2011

Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1035

Published Feb 19, 2011

The password reset in PivotX before 2.2.4 allows remote attackers to modify the passwords of arbitrary users via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2928

Published Feb 16, 2011

The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileg…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4733

Published Feb 15, 2011

WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms have a default…

CVSS 10.0 · Critical

CVE-2010-3925

Published Jan 13, 2011

Contents-Mall before 15 does not properly handle passwords, which allows remote attackers to discover the administrative password, and consequently obtain sensitive information or…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3912

Published Jan 13, 2011

The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vecto…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-5021

Published Dec 9, 2010

Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier for attackers to obtain access by using this password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3038

Published Nov 22, 2010

Cisco Unified Videoconferencing (UVC) System 5110 and 5115, when the Linux operating system is used, has a default password for the (1) root, (2) cs, and (3) develop accounts, whi…

CVSS 10.0 · Critical

CVE-2010-0113

Published Nov 15, 2010

The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assiste…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3897

Published Nov 12, 2010

ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to ob…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0219

Published Oct 18, 2010

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, wh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7261

Published Sep 20, 2010

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3319

Published Sep 13, 2010

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3318

Published Sep 13, 2010

IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 551-575 of 780 CVEsPage 23 of 32