Total
736 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-3684 | 1 Synology | 13 Disk Station Ds1010\+, Disk Station Ds109, Disk Station Ds110\+ and 10 more | 2018-10-10 | 2.1 LOW | N/A |
The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive information by reading a log, a different vulnerability than CVE-2010-2453. | |||||
CVE-2010-2928 | 1 Vmware | 1 Vcenter Server | 2018-10-10 | 2.1 LOW | N/A |
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this file. | |||||
CVE-2010-1573 | 1 Linksys | 1 Wap54gv3 | 2018-10-10 | 10.0 HIGH | N/A |
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 parameters to (a) Debug_command_page.asp and (b) debug.cgi. | |||||
CVE-2010-0616 | 1 Myshell | 1 Evalsmsi | 2018-10-10 | 7.5 HIGH | N/A |
evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability. | |||||
CVE-2010-0556 | 1 Google | 1 Chrome | 2018-10-10 | 4.3 MEDIUM | N/A |
browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element. | |||||
CVE-2010-0124 | 1 Timeclock-software | 1 Employee Timeclock Software | 2018-10-10 | 2.1 LOW | N/A |
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process. | |||||
CVE-2010-0219 | 2 Apache, Sap | 2 Axis2, Businessobjects | 2018-10-10 | 10.0 HIGH | N/A |
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. | |||||
CVE-2009-4945 | 1 Atutor | 1 Acollab | 2018-10-10 | 7.5 HIGH | N/A |
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requests to index.php. | |||||
CVE-2009-4463 | 1 Intellicom | 3 Netbiter Webscada Firmware, Netbiter Webscada Ws100, Netbiter Webscada Ws200 | 2018-10-10 | 10.0 HIGH | N/A |
Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it easier for remote attackers to modify network settings and cause a denial of service. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: this issue was originally reported to be hard-coded passwords, not default passwords. | |||||
CVE-2009-2381 | 1 Gizmo5 | 1 Gizmo | 2018-10-10 | 5.0 MEDIUM | N/A |
Gizmo 3.1.0.79 on Linux does not verify a server's SSL certificate, which allows remote servers to obtain the credentials of arbitrary users via a spoofed certificate. | |||||
CVE-2009-2158 | 1 Torrenttrader | 1 Torrenttrader Classic | 2018-10-10 | 7.5 HIGH | N/A |
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes it easier for remote attackers to obtain a password via a brute-force attack. | |||||
CVE-2009-2358 | 1 Yasinkaplan | 1 Tekradius | 2018-10-10 | 4.6 MEDIUM | N/A |
TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file. | |||||
CVE-2009-2271 | 1 Huawei | 1 D100 | 2018-10-10 | 10.0 HIGH | N/A |
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers to obtain access. | |||||
CVE-2009-2317 | 1 Axesstel | 1 Mv 410r | 2018-10-10 | 10.0 HIGH | N/A |
The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access. | |||||
CVE-2009-1745 | 1 Armorlogic | 1 Profense Web Application Firewall | 2018-10-10 | 10.0 HIGH | N/A |
Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access. | |||||
CVE-2009-1465 | 1 Klinzmann | 1 Application Access Server | 2018-10-10 | 7.5 HIGH | N/A |
Application Access Server (A-A-S) 2.0.48 has "wildbat" as its default password for the admin account, which makes it easier for remote attackers to obtain access. | |||||
CVE-2009-0964 | 1 Xlinesoft | 1 Phprunner | 2018-10-10 | 5.0 MEDIUM | N/A |
UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication. | |||||
CVE-2009-0644 | 1 Swannsecurity | 1 Dvr4-securanet | 2018-10-10 | 5.0 MEDIUM | N/A |
The HTTP interface in Swann DVR4-SecuraNet has a certain default administrative username and password, which makes it easier for remote attackers to obtain privileged access. | |||||
CVE-2016-1491 | 1 Lenovo | 1 Shareit | 2018-10-09 | 5.4 MEDIUM | 8.8 HIGH |
The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area. | |||||
CVE-2015-8362 | 1 Harman | 1 Amx Firmware | 2018-10-09 | 10.0 HIGH | 9.8 CRITICAL |
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984. |