|
314721
|
- |
|
skype
|
skype
|
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*.78 for Windows allows remote authorized attackers to download arbitrary files via a URL that contains …
|
CWE-88
Argument Injection
|
CVE-2006-2312
|
2024-02-14 02:47 |
2006-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314722
|
- |
|
freebsd
|
freebsd
|
The ipfw firewall in FreeBSD 6.0-RELEASE allows remote attackers to cause a denial of service (firewall crash) via ICMP IP fragments that match a reset, reject or unreach action, which leads to an ac…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2006-0054
|
2024-02-14 02:43 |
2006-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314723
|
- |
|
microsoft
|
windows_2000
|
The LDAP client on Microsoft Windows 2000 before Update Rollup 1 for SP4 accepts certificates using LDAP Secure Sockets Layer (LDAPS) even when the Certificate Authority (CA) is not trusted, which co…
|
CWE-295
Improper Certificate Validation
|
CVE-2005-3170
|
2024-02-14 02:43 |
2005-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314724
|
- |
|
openldap
|
openldap
|
ldbm_back_exop_passwd in the back-ldbm backend in passwd.c for OpenLDAP 2.1.12 and earlier, when the slap_passwd_parse function does not return LDAP_SUCCESS, attempts to free an uninitialized pointer…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2003-1201
|
2024-02-14 02:43 |
2003-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314725
|
7.5 |
HIGH
Network
|
cisco
|
unified_wireless_ip_phone_7920_firmware
|
Cisco IP Phone (VoIP) 7920 1.0(8) contains certain hard-coded ("fixed") public and private SNMP community strings that cannot be changed, which allows remote attackers to obtain sensitive information.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-3803
|
2024-02-14 01:48 |
2005-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314726
|
7.5 |
HIGH
Network
|
utstarcom
|
f1000_wi-fi_firmware
|
The SNMP daemon in UTStarcom F1000 VOIP WIFI Phone s2.0 running VxWorks 5.5.1 with kernel WIND 2.6 has hard-coded public credentials that cannot be changed, which allows attackers to obtain sensitive…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-3716
|
2024-02-14 01:48 |
2005-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314727
|
9.8 |
CRITICAL
Network
|
arkeia
|
network_backup
|
Arkeia Network Backup Client 5.x contains hard-coded credentials that effectively serve as a back door, which allows remote attackers to access the file system and possibly execute arbitrary commands.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2005-0496
|
2024-02-14 01:48 |
2005-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314728
|
- |
|
iisprotect
|
iisprotect
|
SQL injection vulnerability in the web-based administration interface for iisPROTECT 2.2-r4, and possibly earlier versions, allows remote attackers to insert arbitrary SQL and execute code via certai…
|
CWE-89
SQL Injection
|
CVE-2003-0377
|
2024-02-14 01:47 |
2003-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314729
|
9.8 |
CRITICAL
Network
|
linksys
|
wap54g_firmware
|
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitr…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2010-1573
|
2024-02-14 01:43 |
2010-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314730
|
5.5 |
MEDIUM
Local
|
pgp
|
personal_privacy
|
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Alw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2002-1696
|
2024-02-14 01:20 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|