|
250931
|
7.5 |
HIGH
Network
|
postgresql
|
postgresql
|
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2002-1657
|
2024-02-9 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250932
|
7.5 |
HIGH
Network
|
typosphere
|
typo
|
Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2008-4905
|
2024-02-9 12:05 |
2008-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250933
|
5.5 |
MEDIUM
Local
|
busybox avaya
|
busybox message_networking aura_sip_enablement_services aura_application_enablement_services messaging_storage_server
|
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2006-1058
|
2024-02-9 12:05 |
2006-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250934
|
7.5 |
HIGH
Network
|
webportal_cms_project
|
webportal_cms
|
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2008-0141
|
2024-02-9 12:04 |
2008-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250935
|
7.5 |
HIGH
Network
|
ibm
|
rational_build_forge
|
IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from cl…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2008-2122
|
2024-02-9 11:54 |
2008-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250936
|
6.1 |
MEDIUM
Network
|
freescripts
|
visitorbook_le
|
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site script…
|
CWE-346
Origin Validation Error
|
CVE-2003-0981
|
2024-02-9 11:53 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250937
|
7.5 |
HIGH
Network
|
6tunnel_project
|
6tunnel
|
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2001-0830
|
2024-02-9 11:52 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250938
|
7.5 |
HIGH
Network
|
clamav apple debian
|
clamav mac_os_x_server debian_linux
|
Clam AntiVirus ClamAV before 0.90 does not close open file descriptors under certain conditions, which allows remote attackers to cause a denial of service (file descriptor consumption and failed sca…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2007-0897
|
2024-02-9 11:48 |
2007-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250939
|
- |
|
apache debian
|
http_server debian_linux
|
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct X…
|
CWE-444
HTTP Request Smuggling
|
CVE-2005-2088
|
2024-02-9 11:40 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250940
|
- |
|
sun
|
java_system_web_server java_system_application_server one_application_server java_system_web_proxy_server
|
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web Server, allows remote attackers to bypas…
|
CWE-444
HTTP Request Smuggling
|
CVE-2006-6276
|
2024-02-9 11:34 |
2006-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|