|
314091
|
7.5 |
HIGH
Network
|
polycom
|
viewstation_512 viewstation_h.323 viewstation_sp_384 viewstation_mp viewstation_128 viewstation_dcp viewstation_v.35 viewstation_fx_vs4000
|
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for remote attackers to guess usernames and passwords via a brute …
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2002-0628
|
2024-02-9 12:14 |
2003-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314092
|
9.8 |
CRITICAL
Network
|
3com
|
superstack_ii_ps_hub_40_firmware
|
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide an incorrect username or password, which makes it easier to break into the ser…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2001-1291
|
2024-02-9 12:14 |
2001-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314093
|
9.8 |
CRITICAL
Network
|
lightwavemo
|
consoleserver_3200_firmware
|
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2001-0395
|
2024-02-9 12:14 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314094
|
9.8 |
CRITICAL
Network
|
archilles
|
newsworld
|
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and s…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2005-3435
|
2024-02-9 12:13 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314095
|
7.5 |
HIGH
Network
|
openssl canonical
|
openssl ubuntu_linux
|
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2005-2946
|
2024-02-9 12:13 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314096
|
- |
|
armagetronad
|
armagetron_advanced armagetron
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) clai…
|
CWE-129
Improper Validation of Array Index
|
CVE-2005-0369
|
2024-02-9 12:13 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314097
|
9.8 |
CRITICAL
Network
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating t…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2005-0408
|
2024-02-9 12:13 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314098
|
7.5 |
HIGH
Network
|
teekai
|
tracking_online
|
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 has…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2002-2058
|
2024-02-9 12:13 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314099
|
7.5 |
HIGH
Network
|
postgresql
|
postgresql
|
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2002-1657
|
2024-02-9 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314100
|
5.5 |
MEDIUM
Local
|
busybox avaya
|
busybox message_networking aura_sip_enablement_services aura_application_enablement_services messaging_storage_server
|
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2006-1058
|
2024-02-9 12:05 |
2006-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|