Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

781 CVEs tagged with CWE-255196 Critical, 164 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2008-3235

Published Jul 21, 2008

Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and att…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3067

Published Jul 7, 2008

sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent proce…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-2857

Published Jun 25, 2008

AlstraSoft AskMe Pro 2.1 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2291

Published May 18, 2008

axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 generates credentials with a fixed salt or without any salt, which makes it easier for remote a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1880

Published May 12, 2008

The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1970

Published Apr 27, 2008

muCommander before 0.8.2 stores credentials.xml with insecure permissions, which allows local users to obtain credentials.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-1542

Published Mar 28, 2008

Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain administrative access via a telnet logi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1393

Published Mar 20, 2008

Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for rem…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-1394

Published Mar 20, 2008

Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1396

Published Mar 20, 2008

Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attack…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1218

Published Mar 10, 2008

Argument injection vulnerability in Dovecot 1.0.x before 1.0.13, and 1.1.x before 1.1.rc3, when using blocking passdbs, allows remote attackers to bypass the password check via a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1184

Published Mar 6, 2008

The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0604

Published Feb 6, 2008

The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6340

Published Feb 5, 2008

Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 701-725 of 781 CVEsPage 29 of 32