Total
725 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0444 | 2 Hp, Sun | 2 Operations Agent, Solaris | 2024-11-21 | 10.0 HIGH | N/A |
HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2010-0229 | 1 Verbatim | 1 Corporate Secure | 2024-11-21 | 4.6 MEDIUM | N/A |
Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time. | |||||
CVE-2010-0227 | 1 Verbatim | 1 Corporate Secure | 2024-11-21 | 4.6 MEDIUM | N/A |
Verbatim Corporate Secure and Corporate Secure FIPS Edition USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program. | |||||
CVE-2010-0226 | 1 Sandisk | 1 Cruzer Enterprise Usb | 2024-11-21 | 4.6 MEDIUM | N/A |
SanDisk Cruzer Enterprise USB flash drives do not prevent password replay attacks, which allows physically proximate attackers to access the cleartext drive contents by providing a key that was captured in a USB data stream at an earlier time. | |||||
CVE-2010-0224 | 1 Sandisk | 1 Cruzer Enterprise Usb | 2024-11-21 | 4.6 MEDIUM | N/A |
SanDisk Cruzer Enterprise USB flash drives validate passwords with a program running on the host computer rather than the device hardware, which allows physically proximate attackers to access the cleartext drive contents via a modified program. | |||||
CVE-2010-0219 | 2 Apache, Sap | 2 Axis2, Businessobjects | 2024-11-21 | 10.0 HIGH | N/A |
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. | |||||
CVE-2010-0141 | 1 Cisco | 1 Unified Meetingplace | 2024-11-21 | 6.4 MEDIUM | N/A |
MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935. | |||||
CVE-2010-0124 | 1 Timeclock-software | 1 Employee Timeclock Software | 2024-11-21 | 2.1 LOW | N/A |
Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process. | |||||
CVE-2010-0113 | 2 Google, Symantec | 2 Android, Mobile Security | 2024-11-21 | 4.3 MEDIUM | N/A |
The Symantec Norton Mobile Security application 1.0 Beta for Android records setup details, possibly including wipe/lock credentials, in the device logs, which allows user-assisted remote attackers to obtain potentially sensitive information by leveraging the ability of a separate crafted application to read these logs. | |||||
CVE-2010-0015 | 1 Gnu | 1 Glibc | 2024-11-21 | 7.5 HIGH | N/A |
nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function. | |||||
CVE-2009-5149 | 1 Arris | 4 Dg860a, Na Model 862 Gw Mono Firmware, Tg862a and 1 more | 2024-11-21 | 4.3 MEDIUM | N/A |
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password of the day" issue. | |||||
CVE-2009-5143 | 1 Gehealthcare | 1 Discovery 530c Firmware | 2024-11-21 | 10.0 HIGH | N/A |
GE Healthcare Discovery 530C has a password of #bigguy1 for the (1) acqservice user and (2) wsservice user of the Xeleris System, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |||||
CVE-2009-5066 | 1 Redhat | 2 Jboss Community Application Server, Jboss Enterprise Application Platform | 2024-11-21 | 2.1 LOW | N/A |
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | |||||
CVE-2009-5021 | 1 Michael Dehaan | 1 Cobbler | 2024-11-21 | 7.5 HIGH | N/A |
Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier for attackers to obtain access by using this password. | |||||
CVE-2009-4945 | 1 Atutor | 1 Acollab | 2024-11-21 | 7.5 HIGH | N/A |
AdPeeps 8.5d1 has a default password of admin for the admin account, which makes it easier for remote attackers to obtain access via requests to index.php. | |||||
CVE-2009-4781 | 1 Tukeva | 1 Password Reminder | 2024-11-21 | 7.2 HIGH | N/A |
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection. | |||||
CVE-2009-4770 | 1 Jasper | 1 Httpdx | 2024-11-21 | 7.5 HIGH | N/A |
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to obtain privileged access. | |||||
CVE-2009-4674 | 1 Mole-group | 2 Bus Ticket Script, Sky Hunter Airline Ticket Sale Script | 2024-11-21 | 7.5 HIGH | N/A |
admin/admin.php in Mole Group Sky Hunter Airline Ticket Sale Script and Bus Ticket Script allows remote attackers to change an arbitrary password via a modified user_id field. | |||||
CVE-2009-4463 | 1 Intellicom | 3 Netbiter Webscada Firmware, Netbiter Webscada Ws100, Netbiter Webscada Ws200 | 2024-11-21 | 10.0 HIGH | N/A |
Intellicom NetBiter WebSCADA devices use default passwords for the HICP network configuration service, which makes it easier for remote attackers to modify network settings and cause a denial of service. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation. NOTE: this issue was originally reported to be hard-coded passwords, not default passwords. | |||||
CVE-2009-4354 | 1 Transware | 1 Active\! Mail | 2024-11-21 | 5.8 MEDIUM | N/A |
TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the "secure" flag for cookies in SSL sessions. |