|
250921
|
9.8 |
CRITICAL
Network
|
lightwavemo
|
consoleserver_3200_firmware
|
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2001-0395
|
2024-02-9 12:14 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250922
|
- |
|
winpcap
|
winpcap
|
Multiple array index errors in the bpf_filter_init function in NPF.SYS in WinPcap before 4.0.2, when run in monitor mode (aka Table Management Extensions or TME), and as used in Wireshark and possibl…
|
CWE-129
Improper Validation of Array Index
|
CVE-2007-5756
|
2024-02-9 12:13 |
2007-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250923
|
9.8 |
CRITICAL
Network
|
extcalendar_project
|
extcalendar
|
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without providing the original password, and possibly perform other unauthorized actions, v…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2007-0681
|
2024-02-9 12:13 |
2007-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250924
|
9.8 |
CRITICAL
Network
|
archilles
|
newsworld
|
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and s…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2005-3435
|
2024-02-9 12:13 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250925
|
7.5 |
HIGH
Network
|
openssl canonical
|
openssl ubuntu_linux
|
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2005-2946
|
2024-02-9 12:13 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250926
|
- |
|
armagetronad
|
armagetron_advanced armagetron
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) clai…
|
CWE-129
Improper Validation of Array Index
|
CVE-2005-0369
|
2024-02-9 12:13 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250927
|
9.8 |
CRITICAL
Network
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating t…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2005-0408
|
2024-02-9 12:13 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250928
|
7.5 |
HIGH
Network
|
teekai
|
tracking_online
|
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 has…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2002-2058
|
2024-02-9 12:13 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250929
|
4.4 |
MEDIUM
Local
|
newsoftwares
|
folder_lock
|
Folder Lock 5.9.5 and earlier uses weak encryption (ROT-25) for the password, which allows local administrators to obtain sensitive information by reading and decrypting the QualityControl\_pack regi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2008-3775
|
2024-02-9 12:10 |
2008-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250930
|
4.6 |
MEDIUM
Physics
|
microsoft
|
windows_mobile
|
Microsoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password over the USB connection from the host to the devi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2007-5460
|
2024-02-9 12:07 |
2007-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|