Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,511 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 139 Low, 0 Unrated.

CVE-2011-4684

Published Dec 7, 2011

Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-4321

Published Nov 23, 2011

The password reset functionality in Joomla! 1.5.x through 1.5.24 uses weak random numbers, which makes it easier for remote attackers to change the passwords of arbitrary users vi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4507

Published Nov 22, 2011

The D-Link DIR-685 router, when certain WPA and WPA2 configurations are used, does not maintain an encrypted wireless network during transfer of a large amount of network traffic,…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4432

Published Nov 10, 2011

www/include/configuration/nconfigObject/contact/DB-Func.php in Merethis Centreon before 2.3.2 does not use a salt during calculation of a password hash, which makes it easier for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3212

Published Oct 14, 2011

CoreStorage in Apple Mac OS X 10.7 before 10.7.2 does not ensure that all disk data is encrypted during the enabling of FileVault, which makes it easier for physically proximate a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3599

Published Oct 10, 2011

The Crypt::DSA (aka Crypt-DSA) module 1.17 and earlier for Perl, when /dev/random is absent, uses the Data::Random module, which makes it easier for remote attackers to spoof a si…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2190

Published Oct 7, 2011

The generate_admin_password function in Cherokee before 1.2.99 uses time and PID values for seeding of a random number generator, which makes it easier for local users to determin…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3692

Published Sep 27, 2011

NetSaro Enterprise Messenger Server 2.0 stores cleartext console credentials in configuration.xml, which allows local users to obtain sensitive information by reading this file an…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3685

Published Sep 27, 2011

Tembria Server Monitor before 6.0.5 Build 2252 uses a substitution cipher to encrypt application credentials, which allows local users to obtain sensitive information by leveragin…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1509

Published Sep 20, 2011

The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3189

Published Aug 25, 2011

The crypt function in PHP 5.3.7, when the MD5 hash type is used, returns the value of the salt argument instead of the hashed string, which might allow remote attackers to bypass…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2736

Published Aug 25, 2011

RSA enVision 4.x before 4 SP4 P3 places cleartext administrative credentials in Task Escalation e-mail messages, which allows remote attackers to obtain sensitive information by s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5084

Published Aug 12, 2011

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3009

Published Aug 5, 2011

Ruby before 1.8.6-p114 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging kno…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2686

Published Aug 5, 2011

Ruby before 1.8.7-p352 does not reset the random seed upon forking, which makes it easier for context-dependent attackers to predict the values of random numbers by leveraging kno…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2344

Published Jul 8, 2011

Android Picasa in Android 3.0 and 2.x through 2.3.4 uses a cleartext HTTP session when transmitting the authToken obtained from ClientLogin, which allows remote attackers to gain…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 2,226-2,250 of 2,511 CVEsPage 90 of 101