Skip to main content

CWE archive

CWE-255 CVEs

Programmatic archive

780 CVEs tagged with CWE-255196 Critical, 163 High, 307 Medium, 114 Low, 0 Unrated.

CVE-2016-8962

Published Apr 26, 2017

IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 1188…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8109

Published Apr 24, 2017

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials…

CVSS 7.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-8626

Published Mar 23, 2017

The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPass…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4670

Published Feb 20, 2017

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "Security" component. It allows local user…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-9355

Published Feb 13, 2017

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physi…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2016-8375

Published Feb 13, 2017

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthoriz…

CVSS 4.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2016-8566

Published Feb 13, 2017

An issue was discovered in Siemens SICAM PAS before 8.00. Because of Storing Passwords in a Recoverable Format, an authenticated local attacker with certain privileges could possi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8378

Published Feb 13, 2017

An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9739

Published Feb 1, 2017

IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a local user.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8918

Published Feb 1, 2017

IBM Integration Bus, under non default configurations, could allow a remote user to authenticate without providing valid credentials.

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5950

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated user.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9081

Published Jan 23, 2017

Joomla! 3.4.4 through 3.6.3 allows attackers to reset username, password, and user group assignments and possibly perform other user account modifications via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10103

Published Jan 23, 2017

Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encry…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10101

Published Jan 23, 2017

Information Disclosure can occur in Hitek Software's Automize 10.x and 11.x passManager.jsd. Users have the Read attribute, which allows an attacker to recover the encrypted passw…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3130

Published Jan 13, 2017

An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to obtain local or domai…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 126-150 of 780 CVEsPage 6 of 32