Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2011-2142
The Web Client Service in IBM Datacap Taskmaster Capture 8.0.1 before FP1 requires a cleartext password, which has unspecified impact and attack vect…
Datacap Taskmaster Capture
No fix yet
MEDIUM 5.0
CVE-2010-0216
authenticate_ad_setup_finished.cfm in MediaCAST 8 and earlier allows remote attackers to discover usernames and cleartext passwords by reading the er…
Mediacast
after 8
MEDIUM 5.0
CVE-2011-1789
The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x …
Esx
Patch available
HIGH 7.5
CVE-2011-1655EPSS 12%
The management.asmx module in the Management Web Service in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before SE2 sends a …
Total Defense
Mitigation only
HIGH 10.0
CVE-2011-0935
The PKI functionality in Cisco IOS 15.0 and 15.1 does not prevent permanent caching of certain public keys, which allows remote attackers to bypass a…
iOS
Mitigation only
MEDIUM 5.0
CVE-2011-1673
BackupConfig.php on the NetGear ProSafe WNAP210 allows remote attackers to obtain the administrator password by reading the configuration file.
Prosafe Wnap210
Mitigation only
MEDIUM 5.0
CVE-2009-5057
The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, whic…
Otrs
after 2.3.3
MEDIUM 5.0
CVE-2011-1433
The (1) AgentInterface and (2) CustomerInterface components in Open Ticket Request System (OTRS) before 3.0.6 place cleartext credentials into the se…
Otrs
after 3.0.5
MEDIUM 5.0
CVE-2011-0436
The register_user function in client/new_account_form.php in Domain Technologie Control (DTC) before 0.32.9 includes a cleartext password in an e-mai…
Domain Technologie Control
after 0.32.8
HIGH 9.3
CVE-2011-0724
The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installat…
Edubuntu
Mitigation only
MEDIUM 5.0
CVE-2011-0281
The unparse implementation in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.6.x through 1.9, when an LDAP backend is used, allows …
Kerberos
Mitigation only
HIGH 7.2
CVE-2011-0043
Kerberos in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 supports weak hashing algorithms, which allows local users to gain privileges by ope…
Windows 2003 Server
Mitigation only
MEDIUM 5.0
CVE-2010-4728
Zikula before 1.3.1 uses the rand and srand PHP functions for random number generation, which makes it easier for remote attackers to defeat protecti…
Zikula Application Framework
after 1.2.5
MEDIUM 6.2
CVE-2010-4506
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without aut…
Passlogix V Go Self Service Password Reset And Oem
Mitigation only
MEDIUM 5.0
CVE-2011-0410
CollabNet ScrumWorks Basic 1.8.4 uses cleartext credentials for network communication and the internal database, which makes it easier for context-de…
Scrumworks
Mitigation only
MEDIUM 6.4
CVE-2011-0002
libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obta…
Libuser
after 0.56.18
MEDIUM 5.1
CVE-2010-4626
The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand function, which makes it easi…
Mybb
after 1.4.11
MEDIUM 5.8
CVE-2009-5032
The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes…
Lotus Notes Traveler
after 8.5.0.1
MEDIUM 6.3
CVE-2010-4020
MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (…
Kerberos 5
Patch available
MEDIUM 5.0
CVE-2010-4311
Free Simple Software 1.0 stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information.
Free Simple Software
Mitigation only
MEDIUM 6.4
CVE-2010-4304
The web interface in Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (…
Unified Videoconferencing System 5110 Firmware
Mitigation only
MEDIUM 5.0
CVE-2010-4305
Cisco Unified Videoconferencing (UVC) System 3545, 5110, 5115, and 5230; Unified Videoconferencing 3527 Primary Rate Interface (PRI) Gateway; Unified…
Unified Videoconferencing System 5110 Firmware
Mitigation only
MEDIUM 5.0
CVE-2010-3804EPSS 9%
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, us…
Safari
after 5.0.2
HIGH 7.5
CVE-2009-5014
The default quickstart configuration of TurboGears2 (aka tg2) before 2.0.2 has a weak cookie salt, which makes it easier for remote attackers to bypa…
Turbogears2
after 2.1b2
MEDIUM 5.0
CVE-2010-4184
NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote att…
Netsupport Manager
after 11.00
HIGH 7.5
CVE-2010-3173
The SSL implementation in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey befor…
Firefox
after 3.5.13
MEDIUM 5.0
CVE-2010-4007
Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform succes…
Mojarra
Mitigation only
MEDIUM 5.0
CVE-2010-2057
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a M…
Myfaces
Patch available
MEDIUM 5.0
CVE-2010-3075
EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local user…
Encfs
after 1.6.0
MEDIUM 5.8
CVE-2010-3171
The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random …
Firefox
No fix yet