Vulnerabilities (CVE)

Filtered by CWE-254
Total 407 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-6050 1 Phpmyfaq 1 Phpmyfaq 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
CVE-2014-5334 1 Freenas 1 Freenas 2024-11-21 10.0 HIGH 9.8 CRITICAL
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
CVE-2014-1428 1 Canonical 1 Metal As A Service 2024-11-21 5.0 MEDIUM 2.0 LOW
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.
CVE-2014-10063 1 Qualcomm 4 Mdm9625, Mdm9625 Firmware, Sd 800 and 1 more 2024-11-21 5.0 MEDIUM 7.5 HIGH
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625 and SD 800, a fuse is not correctly blown on a secure device.
CVE-2011-4889 1 Ibm 1 Websphere Application Server 2024-11-21 7.5 HIGH 9.8 CRITICAL
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a configuration using Tivoli Directory Server, which might allow remote attackers to gain access to an application by leveraging knowledge of an old password. IBM X-Force ID: 72581.
CVE-2011-3145 1 Mount.ecrpytfs Private Project 1 Mount.ecrpytfs Private 2024-11-21 7.5 HIGH 3.8 LOW
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
CVE-2009-5144 1 Mod Gnutls Project 1 Mod Gnutls 2024-11-21 5.0 MEDIUM 7.5 HIGH
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.