Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2008-02-08 CVE-2008-0662 Incorrect Permission Assignment for Critical Resource vulnerability in Checkpoint Vpn-1 Secureclient Ngair56/Ngxr60
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.
local
low complexity
checkpoint CWE-732
7.8
2008-02-07 CVE-2008-0655 Unspecified vulnerability in Adobe Acrobat
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
network
low complexity
adobe
critical
9.8
2008-01-29 CVE-2008-0174 Cleartext Storage of Sensitive Information vulnerability in GE Proficy Real-Time Information Portal 2.6
GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the passwords and gain privileges.
network
low complexity
ge CWE-312
critical
9.8
2008-01-22 CVE-2008-0374 Cleartext Transmission of Sensitive Information vulnerability in OKI C5510Mfp Firmware 1.01
OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.
network
low complexity
oki CWE-319
7.5
2008-01-16 CVE-2008-0081 Use of Uninitialized Resource vulnerability in Microsoft Excel, Excel Viewer and Office
Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
network
low complexity
microsoft CWE-908
critical
9.8
2008-01-08 CVE-2008-0141 Use of Insufficiently Random Values vulnerability in Webportal CMS Project Webportal CMS 0.6.0
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.
network
low complexity
webportal-cms-project CWE-330
7.5
2007-11-20 CVE-2007-6033 Incorrect Permission Assignment for Critical Resource vulnerability in Wonderware Intouch 8.0
Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers, and possibly anonymous users, to execute arbitrary programs.
network
low complexity
wonderware CWE-732
8.8
2007-11-19 CVE-2007-6013 Use of a Broken or Risky Cryptographic Algorithm vulnerability in multiple products
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
network
low complexity
wordpress fedoraproject CWE-327
critical
9.8
2007-11-15 CVE-2007-4268 Incorrect Conversion between Numeric Types vulnerability in Apple mac OS X
Integer signedness error in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk message with a negative value, which satisfies a signed comparison during mbuf allocation but is later interpreted as an unsigned value, which triggers a heap-based buffer overflow.
local
low complexity
apple CWE-681
7.8
2007-11-15 CVE-2007-3749 Improper Initialization vulnerability in Apple mac OS X
The kernel in Apple Mac OS X 10.4 through 10.4.10 does not reset the current Mach Thread Port or Thread Exception Port when executing a setuid program, which allows local users to execute arbitrary code by creating the port before launching the setuid program, then writing to the address space of the setuid process.
local
low complexity
apple CWE-665
7.8