Total
736 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-4005 | 1 Sap | 1 Brazil | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP Brazil add-on has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4004 | 1 Sap | 1 Project System | 2014-06-17 | 5.0 MEDIUM | N/A |
The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4007 | 1 Sap | 1 Upgrade Tools | 2014-06-17 | 5.0 MEDIUM | N/A |
The SAP Upgrade tools for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4010 | 1 Sap | 1 Transaction Data Pool | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP Transaction Data Pool has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4011 | 1 Sap | 1 Capacity Leveling | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP Capacity Leveling has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4012 | 1 Sap | 1 Open Hub Service | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP Open Hub Service has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4008 | 1 Sap | 1 Web Services Tool | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP Web Services Tool (CA-WUI-WST) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4006 | 1 Sap | 1 Oil Industry Solution Traders And Schedulers Workbench | 2014-06-17 | 5.0 MEDIUM | N/A |
The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-4009 | 1 Sap | 1 Computing Center Management System Monitoring | 2014-06-17 | 5.0 MEDIUM | N/A |
SAP CCMS Monitoring (BC-CCM-MON) has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-2752 | 1 Sap | 1 Business Object Processing Framework For Abap | 2014-06-17 | 7.5 HIGH | N/A |
SAP Business Object Processing Framework (BOPF) for ABAP has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-2751 | 1 Sap | 1 Print And Output Management | 2014-06-17 | 7.5 HIGH | N/A |
SAP Print and Output Management has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. | |||||
CVE-2014-2354 | 1 Cogentdatahub | 1 Cogent Datahub | 2014-06-05 | 5.0 MEDIUM | N/A |
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack. | |||||
CVE-2014-0246 | 1 Sosreport Project | 1 Sosreport | 2014-05-30 | 4.3 MEDIUM | N/A |
SOSreport stores the md5 hash of the GRUB bootloader password in an archive, which allows local users to obtain sensitive information by reading the archive. | |||||
CVE-2014-2350 | 1 Emerson | 1 Deltav | 2014-05-23 | 7.5 HIGH | N/A |
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program. | |||||
CVE-2014-3220 | 1 F5 | 1 Big-iq | 2014-05-22 | 9.0 HIGH | N/A |
F5 BIG-IQ Cloud and Security 4.0.0 through 4.1.0 allows remote authenticated users to change the password of arbitrary users via the name parameter in a request to the user's page in mgmt/shared/authz/users/. | |||||
CVE-2013-7382 | 1 Vicidial | 1 Vicidial | 2014-05-19 | 5.0 MEDIUM | N/A |
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access. | |||||
CVE-2014-1849 | 1 Foscam | 1 Ip Camera Firmware | 2014-05-14 | 10.0 HIGH | N/A |
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifying arbitrary camera records in the Foscam DNS server. | |||||
CVE-2014-1408 | 1 Conceptronic | 2 C54apm, C54apm Firmware | 2014-05-05 | 7.8 HIGH | N/A |
The Conceptronic C54APM access point with runtime code 1.26 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via an HTTP request, as demonstrated by stored XSS attacks. | |||||
CVE-2013-7134 | 1 Phusion | 1 Juvia | 2014-04-29 | 7.5 HIGH | N/A |
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cookies. | |||||
CVE-2013-4285 | 1 Dkorunic | 1 Pam S\/key | 2014-04-29 | 2.1 LOW | N/A |
A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local users to obtain sensitive information by reading system memory. |