|
313711
|
9.8 |
CRITICAL
Network
|
lightwavemo
|
consoleserver_3200_firmware
|
Lightwave ConsoleServer 3200 does not disconnect users after unsuccessful login attempts, which could allow remote attackers to conduct brute force password guessing.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2001-0395
|
2024-02-9 12:14 |
2001-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313712
|
9.8 |
CRITICAL
Network
|
archilles
|
newsworld
|
admin_news.php in Archilles Newsworld up to 1.3.0 allows attackers to bypass authentication by obtaining the password hash for another user, for example through another Newsworld vulnerability, and s…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2005-3435
|
2024-02-9 12:13 |
2005-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313713
|
7.5 |
HIGH
Network
|
openssl canonical
|
openssl ubuntu_linux
|
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certi…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2005-2946
|
2024-02-9 12:13 |
2005-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313714
|
- |
|
armagetronad
|
armagetron_advanced armagetron
|
Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) clai…
|
CWE-129
Improper Validation of Array Index
|
CVE-2005-0369
|
2024-02-9 12:13 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313715
|
9.8 |
CRITICAL
Network
|
citrusdb
|
citrusdb
|
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows remote attackers to bypass authentication and gain privileges by calculating t…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2005-0408
|
2024-02-9 12:13 |
2005-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313716
|
7.5 |
HIGH
Network
|
teekai
|
tracking_online
|
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 has…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2002-2058
|
2024-02-9 12:13 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313717
|
7.5 |
HIGH
Network
|
postgresql
|
postgresql
|
PostgreSQL uses the username for a salt when generating passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2002-1657
|
2024-02-9 12:06 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313718
|
5.5 |
MEDIUM
Local
|
busybox avaya
|
busybox message_networking aura_sip_enablement_services aura_application_enablement_services messaging_storage_server
|
BusyBox 1.1.1 does not use a salt when generating passwords, which makes it easier for local users to guess passwords from a stolen password file using techniques such as rainbow tables.
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2006-1058
|
2024-02-9 12:05 |
2006-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313719
|
6.1 |
MEDIUM
Network
|
freescripts
|
visitorbook_le
|
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which allows remote attackers to spoof the origin of their incoming requests and facilitate cross-site script…
|
CWE-346
Origin Validation Error
|
CVE-2003-0981
|
2024-02-9 11:53 |
2004-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313720
|
7.5 |
HIGH
Network
|
6tunnel_project
|
6tunnel
|
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers to cause a denial of service (resource exhaustion) by repeatedly connecting to …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2001-0830
|
2024-02-9 11:52 |
2001-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|