Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
Datacap Taskmaster Capture MEDIUM 5.0
CVE-2011-2142

The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vect…

No fix yet
Fix from $1,600 2011-05-16
Mediacast MEDIUM 5.0
CVE-2010-0216

authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the er…

Fix: after 8
Fix from $1,600 2011-05-10
Esx MEDIUM 5.0
CVE-2011-1789

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x …

Patch available
Fix from $1,600 2011-05-09
Total Defense HIGH 7.5
CVE-2011-1655EPSS 12%

The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a …

Mitigation only
Fix from $1,950 2011-04-18
iOS HIGH 10.0
CVE-2011-0935

The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass a…

Mitigation only
Fix from $1,950 2011-04-14
Prosafe Wnap210 MEDIUM 5.0
CVE-2011-1673

BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file.

Mitigation only
Fix from $1,600 2011-04-10
Otrs MEDIUM 5.0
CVE-2009-5057

The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, whic…

Fix: after 2.3.3
Fix from $1,600 2011-03-18
Otrs MEDIUM 5.0
CVE-2011-1433

The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the se…

Fix: after 3.0.5
Fix from $1,600 2011-03-18
Domain Technologie Control MEDIUM 5.0
CVE-2011-0436

The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mai…

Fix: after 0.32.8
Fix from $1,600 2011-03-07
Edubuntu HIGH 9.3
CVE-2011-0724

The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installat…

Mitigation only
Fix from $1,950 2011-02-19
Kerberos MEDIUM 5.0
CVE-2011-0281

The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows …

Mitigation only
Fix from $1,600 2011-02-10
Windows 2003 Server HIGH 7.2
CVE-2011-0043

Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by ope…

Mitigation only
Fix from $1,950 2011-02-10
Zikula Application Framework MEDIUM 5.0
CVE-2010-4728

Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protecti…

Fix: after 1.2.5
Fix from $1,600 2011-02-08
Passlogix V Go Self Service Password Reset And Oem MEDIUM 6.2
CVE-2010-4506

Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without aut…

Mitigation only
Fix from $1,600 2011-02-07
Scrumworks MEDIUM 5.0
CVE-2011-0410

CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-de…

Mitigation only
Fix from $1,600 2011-01-24
Libuser MEDIUM 6.4
CVE-2011-0002

libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obta…

Fix: after 0.56.18
Fix from $1,600 2011-01-22
Mybb MEDIUM 5.1
CVE-2010-4626

The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easi…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Lotus Notes Traveler MEDIUM 5.8
CVE-2009-5032

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes…

Fix: after 8.5.0.1
Fix from $1,600 2010-12-16
Kerberos 5 MEDIUM 6.3
CVE-2010-4020

MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (…

Patch available
Fix from $1,600 2010-12-02
Free Simple Software MEDIUM 5.0
CVE-2010-4311

Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.

Mitigation only
Fix from $1,600 2010-11-26
Unified Videoconferencing System 5110 Firmware MEDIUM 6.4
CVE-2010-4304

The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (…

Mitigation only
Fix from $1,600 2010-11-22
Unified Videoconferencing System 5110 Firmware MEDIUM 5.0
CVE-2010-4305

Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified…

Mitigation only
Fix from $1,600 2010-11-22
Safari MEDIUM 5.0
CVE-2010-3804EPSS 9%

The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, us…

Fix: after 5.0.2
Fix from $1,600 2010-11-22
Turbogears2 HIGH 7.5
CVE-2009-5014

The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypa…

Fix: after 2.1b2
Fix from $1,950 2010-11-06
Netsupport Manager MEDIUM 5.0
CVE-2010-4184

NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote att…

Fix: after 11.00
Fix from $1,600 2010-11-05
Firefox HIGH 7.5
CVE-2010-3173

The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey befor…

Fix: after 3.5.13
Fix from $1,950 2010-10-21
Mojarra MEDIUM 5.0
CVE-2010-4007

Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform succes…

Mitigation only
Fix from $1,600 2010-10-20
Myfaces MEDIUM 5.0
CVE-2010-2057

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M…

Patch available
Fix from $1,600 2010-10-20
Encfs MEDIUM 5.0
CVE-2010-3075

EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local user…

Fix: after 1.6.0
Fix from $1,600 2010-09-17
Firefox MEDIUM 5.8
CVE-2010-3171

The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random …

No fix yet
Fix from $1,600 2010-09-15