Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2010-3264

Published Sep 8, 2010

The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by r…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3122

Published Aug 25, 2010

The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1760

Published Aug 19, 2010

loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2966

Published Aug 5, 2010

The INCLUDE_SECURITY functionality in Wind River VxWorks 6.x, 5.x, and earlier uses the LOGIN_USER_NAME and LOGIN_USER_PASSWORD (aka LOGIN_PASSWORD) parameters to create hardcoded…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4945

Published Jul 22, 2010

AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requests to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-2083

Published May 26, 2010

Microsoft Dynamics GP has a default value of ACCESS for the system password, which might make it easier for remote authenticated users to bypass intended access restrictions via u…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2082

Published May 26, 2010

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1940

Published May 14, 2010

Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4781

Published Apr 21, 2010

TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7255

Published Apr 20, 2010

login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unatt…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1487

Published Apr 20, 2010

IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4770

Published Apr 20, 2010

The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to ob…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0769

Published Apr 1, 2010

IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, wh…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0510

Published Mar 30, 2010

Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an e…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1135

Published Mar 27, 2010

The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0570

Published Mar 5, 2010

Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote attackers to execute arbitrary cod…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 576-600 of 780 CVEsPage 24 of 32