Vulnerability index

Browse CVEs

2,155 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cryptographic IssuesCWE-310 × clear
MEDIUM 5.0 CVE-2011-2142 The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vect… Datacap Taskmaster Capture No fix yet Fix from $1,6002011-05-16 MEDIUM 5.0 CVE-2010-0216 authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the er… Mediacast after 8 Fix from $1,6002011-05-10 MEDIUM 5.0 CVE-2011-1789 The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x … Esx Patch available Fix from $1,6002011-05-09 HIGH 7.5 CVE-2011-1655EPSS 12% The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a … Total Defense Mitigation only Fix from $1,9502011-04-18 HIGH 10.0 CVE-2011-0935 The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass a… iOS Mitigation only Fix from $1,9502011-04-14 MEDIUM 5.0 CVE-2011-1673 BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file. Prosafe Wnap210 Mitigation only Fix from $1,6002011-04-10 MEDIUM 5.0 CVE-2009-5057 The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, whic… Otrs after 2.3.3 Fix from $1,6002011-03-18 MEDIUM 5.0 CVE-2011-1433 The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the se… Otrs after 3.0.5 Fix from $1,6002011-03-18 MEDIUM 5.0 CVE-2011-0436 The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mai… Domain Technologie Control after 0.32.8 Fix from $1,6002011-03-07 HIGH 9.3 CVE-2011-0724 The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installat… Edubuntu Mitigation only Fix from $1,9502011-02-19 MEDIUM 5.0 CVE-2011-0281 The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows … Kerberos Mitigation only Fix from $1,6002011-02-10 HIGH 7.2 CVE-2011-0043 Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by ope… Windows 2003 Server Mitigation only Fix from $1,9502011-02-10 MEDIUM 5.0 CVE-2010-4728 Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protecti… Zikula Application Framework after 1.2.5 Fix from $1,6002011-02-08 MEDIUM 6.2 CVE-2010-4506 Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without aut… Passlogix V Go Self Service Password Reset And Oem Mitigation only Fix from $1,6002011-02-07 MEDIUM 5.0 CVE-2011-0410 CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-de… Scrumworks Mitigation only Fix from $1,6002011-01-24 MEDIUM 6.4 CVE-2011-0002 libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obta… Libuser after 0.56.18 Fix from $1,6002011-01-22 MEDIUM 5.1 CVE-2010-4626 The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easi… Mybb after 1.4.11 Fix from $1,6002010-12-30 MEDIUM 5.8 CVE-2009-5032 The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes… Lotus Notes Traveler after 8.5.0.1 Fix from $1,6002010-12-16 MEDIUM 6.3 CVE-2010-4020 MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (… Kerberos 5 Patch available Fix from $1,6002010-12-02 MEDIUM 5.0 CVE-2010-4311 Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. Free Simple Software Mitigation only Fix from $1,6002010-11-26 MEDIUM 6.4 CVE-2010-4304 The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (… Unified Videoconferencing System 5110 Firmware Mitigation only Fix from $1,6002010-11-22 MEDIUM 5.0 CVE-2010-4305 Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified… Unified Videoconferencing System 5110 Firmware Mitigation only Fix from $1,6002010-11-22 MEDIUM 5.0 CVE-2010-3804EPSS 9% The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, us… Safari after 5.0.2 Fix from $1,6002010-11-22 HIGH 7.5 CVE-2009-5014 The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypa… Turbogears2 after 2.1b2 Fix from $1,9502010-11-06 MEDIUM 5.0 CVE-2010-4184 NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote att… Netsupport Manager after 11.00 Fix from $1,6002010-11-05 HIGH 7.5 CVE-2010-3173 The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey befor… Firefox after 3.5.13 Fix from $1,9502010-10-21 MEDIUM 5.0 CVE-2010-4007 Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform succes… Mojarra Mitigation only Fix from $1,6002010-10-20 MEDIUM 5.0 CVE-2010-2057 shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M… Myfaces Patch available Fix from $1,6002010-10-20 MEDIUM 5.0 CVE-2010-3075 EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local user… Encfs after 1.6.0 Fix from $1,6002010-09-17 MEDIUM 5.8 CVE-2010-3171 The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random … Firefox No fix yet Fix from $1,6002010-09-15