|
313321
|
7.5 |
HIGH
Network
|
openssl canonical
|
openssl ubuntu_linux
|
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2005-2946
|
2024-02-9 12:13 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313322
|
- |
|
armagetronad
|
armagetron_advanced armagetron
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) clai…
|
CWE-129
Improper Validation of Array Index
|
CVE-2005-0369
|
2024-02-9 12:13 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313323
|
9.8 |
CRITICAL
Network
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating t…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2005-0408
|
2024-02-9 12:13 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313324
|
7.5 |
HIGH
Network
|
teekai
|
tracking_online
|
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 has…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2002-2058
|
2024-02-9 12:13 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313325
|
7.5 |
HIGH
Network
|
postgresql
|
postgresql
|
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2002-1657
|
2024-02-9 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313326
|
5.5 |
MEDIUM
Local
|
busybox avaya
|
busybox message_networking aura_sip_enablement_services aura_application_enablement_services messaging_storage_server
|
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2006-1058
|
2024-02-9 12:05 |
2006-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313327
|
6.1 |
MEDIUM
Network
|
freescripts
|
visitorbook_le
|
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site script…
|
CWE-346
Origin Validation Error
|
CVE-2003-0981
|
2024-02-9 11:53 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313328
|
7.5 |
HIGH
Network
|
6tunnel_project
|
6tunnel
|
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2001-0830
|
2024-02-9 11:52 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313329
|
- |
|
apache debian
|
http_server debian_linux
|
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct X…
|
CWE-444
HTTP Request Smuggling
|
CVE-2005-2088
|
2024-02-9 11:40 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313330
|
- |
|
microsoft
|
internet_information_services
|
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chun…
|
CWE-444
HTTP Request Smuggling
|
CVE-2005-2089
|
2024-02-9 11:29 |
2005-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|