Total
725 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2009-4304 | 1 Moodle | 1 Moodle | 2024-11-21 | 7.5 HIGH | N/A |
Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks. | |||||
CVE-2009-4189 | 1 Hp | 1 Operations Manager | 2024-11-21 | 10.0 HIGH | N/A |
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3099 and CVE-2009-3843. | |||||
CVE-2009-4188 | 1 Hp | 1 Operations Dashboard | 2024-11-21 | 10.0 HIGH | N/A |
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers to execute arbitrary code via a session that uses the manager role to conduct unrestricted file upload attacks against the /manager servlet in the Tomcat servlet container. NOTE: this might overlap CVE-2009-3098. | |||||
CVE-2009-4096 | 1 Scriptlerim | 1 Radio Isetek Scripti | 2024-11-21 | 7.5 HIGH | N/A |
RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc. | |||||
CVE-2009-3710 | 1 Riorey | 1 Rios | 2024-11-21 | 10.0 HIGH | N/A |
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022. | |||||
CVE-2009-3677 | 1 Microsoft | 5 Windows 2000, Windows Server 2003, Windows Server 2008 and 2 more | 2024-11-21 | 10.0 HIGH | N/A |
The Internet Authentication Service (IAS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly verify the credentials in an MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication request, which allows remote attackers to access network resources via a malformed request, aka "MS-CHAP Authentication Bypass Vulnerability." | |||||
CVE-2009-3548 | 1 Apache | 1 Tomcat | 2024-11-21 | 7.5 HIGH | N/A |
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a blank default password for the administrative user, which allows remote attackers to gain privileges. | |||||
CVE-2009-3516 | 1 Ibm | 1 Aix | 2024-11-21 | 7.2 HIGH | N/A |
gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors. | |||||
CVE-2009-3180 | 1 Anantasoft | 1 Gazelle Cms | 2024-11-21 | 7.5 HIGH | N/A |
Anantasoft Gazelle CMS 1.0 allows remote attackers to conduct a password reset for other users via a modified user parameter to renew.php. | |||||
CVE-2009-3166 | 1 Mozilla | 1 Bugzilla | 2024-11-21 | 5.0 MEDIUM | N/A |
token.cgi in Bugzilla 3.4rc1 through 3.4.1 places a password in a URL at the beginning of a login session that occurs immediately after a password reset, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | |||||
CVE-2009-3035 | 1 Symantec | 1 Altiris Notification Server | 2024-11-21 | 4.3 MEDIUM | N/A |
The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials. | |||||
CVE-2009-2945 | 1 Stanford | 1 Webauth | 2024-11-21 | 4.3 MEDIUM | N/A |
weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | |||||
CVE-2009-2829 | 1 Apple | 1 Mac Os X Server | 2024-11-21 | 5.0 MEDIUM | N/A |
Event Monitor in Apple Mac OS X 10.5.8 does not properly handle crafted authentication data sent to an SSH daemon, which allows remote attackers to cause a denial of service via vectors involving processing of XML log documents by other services, related to a "log injection" issue. | |||||
CVE-2009-2762 | 1 Wordpress | 1 Wordpress | 2024-11-21 | 7.5 HIGH | N/A |
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array. | |||||
CVE-2009-2508 | 1 Microsoft | 2 Windows Server 2003, Windows Server 2008 | 2024-11-21 | 6.9 MEDIUM | N/A |
The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser's cache, aka "Single Sign On Spoofing in ADFS Vulnerability." | |||||
CVE-2009-2435 | 1 Ibm | 1 Lotus Instant Messaging And Web Conferencing | 2024-11-21 | 5.0 MEDIUM | N/A |
The Sametime server in IBM Lotus Instant Messaging and Web Conferencing 6.5.1 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | |||||
CVE-2009-2429 | 1 Mcafee | 1 Smartfilter | 2024-11-21 | 4.6 MEDIUM | N/A |
SmartFilter Web Gateway Security 4.2.1.00 stores user credentials in cleartext in admin_backup.xml files and uses insecure permissions for these files, which allows local users to gain privileges. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2009-2381 | 1 Gizmo5 | 1 Gizmo | 2024-11-21 | 5.0 MEDIUM | N/A |
Gizmo 3.1.0.79 on Linux does not verify a server's SSL certificate, which allows remote servers to obtain the credentials of arbitrary users via a spoofed certificate. | |||||
CVE-2009-2374 | 1 Drupal | 1 Drupal | 2024-11-21 | 4.3 MEDIUM | N/A |
Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. | |||||
CVE-2009-2358 | 1 Yasinkaplan | 1 Tekradius | 2024-11-21 | 4.6 MEDIUM | N/A |
TekRADIUS 3.0 uses BUILTIN\Users:R permissions for the TekRADIUS.ini file, which allows local users to obtain obfuscated database credentials by reading this file. |