Skip to main content

CWE archive

CWE-310 CVEs

Programmatic archive

2,510 CVEs tagged with CWE-31058 Critical, 302 High, 2,012 Medium, 138 Low, 0 Unrated.

CVE-2011-0009

Published Jan 25, 2011

Best Practical Solutions RT 3.x before 3.8.9rc2 and 4.x before 4.0.0rc4 uses the MD5 algorithm for password hashes, which makes it easier for context-dependent attackers to determ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0410

Published Jan 24, 2011

CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-dependent attackers to obtain se…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-0002

Published Jan 22, 2011

libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4334

Published Jan 14, 2011

The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, wh…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4626

Published Dec 30, 2010

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easier for remote attackers to obt…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4584

Published Dec 22, 2010

Opera before 11.00, when Opera Turbo is used, does not properly present information about problematic X.509 certificates on https web sites, which might make it easier for remote…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5032

Published Dec 16, 2010

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easie…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-7270

Published Dec 6, 2010

OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4020

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1324

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain pr…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1323

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-2637

Published Nov 12, 2010

IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sen…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5014

Published Nov 6, 2010

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypass repoze.who authentication v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4184

Published Nov 5, 2010

NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote attackers to obtain potentially s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 2,276-2,300 of 2,510 CVEsPage 92 of 101