Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2011-1128

Published Jun 21, 2011

The loadUserSettings function in Load.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly handle invalid login attempts, which might make i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1945

Published May 31, 2011

The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0766

Published May 31, 2011

The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14B03, uses predictable seeds based on th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2151

Published May 20, 2011

The (1) Admin/frmEmailReportSettings.aspx, (2) Admin/frmGeneralSettings.aspx, (3) Admin/frmSite.aspx, (4) Client/frmUser.aspx, and (5) Login.aspx components in the SmarterTools Sm…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1327

Published May 20, 2011

The Keystroke Encryption feature in Trend Micro Internet Security 2009 (aka Virus Buster 2009 and PC-cillin 2009) does not completely encrypt passwords, which allows local users t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0217

Published May 20, 2011

Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions or cause a denial of service (…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2142

Published May 16, 2011

The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0216

Published May 10, 2011

authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the error messages returned for requ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1789

Published May 9, 2011

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMwar…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1209

Published May 4, 2011

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.39 and 7.0 before 7.0.0.17 uses a weak WS-Security XML encryption algorithm, which makes it easier for remote attackers to…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1655

Published Apr 18, 2011

The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a cleartext response to unspecif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-0935

Published Apr 14, 2011

The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass authentication and have unspeci…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1433

Published Mar 18, 2011

The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the session data in the database, wh…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4758

Published Mar 18, 2011

installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, whi…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5057

Published Mar 18, 2011

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for rem…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0442

Published Mar 16, 2011

The service utility in EMC Avamar 5.x before 5.0.4 uses cleartext to transmit event details in (1) service requests and (2) e-mail messages, which might allow remote attackers to…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-0436

Published Mar 7, 2011

The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mail message, which makes it easi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0724

Published Feb 19, 2011

The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0281

Published Feb 10, 2011

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows remote attackers to cause a de…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4728

Published Feb 8, 2011

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protection mechanisms based on randomi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,251-2,275 of 2,510 CVEsPage 91 of 101