Vulnerabilities > Credentials Management

DATE CVE VULNERABILITY TITLE RISK
2018-11-18 CVE-2008-7320 Credentials Management vulnerability in Gnome Seahorse
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked.
low complexity
gnome CWE-255
6.8
2018-08-23 CVE-2003-1605 Credentials Management vulnerability in Haxx Curl
curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.
network
low complexity
haxx CWE-255
7.5
2018-08-01 CVE-2016-8616 Credentials Management vulnerability in Haxx Curl
A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with the existing connections.
network
high complexity
haxx CWE-255
5.9
2018-07-13 CVE-2016-6554 Credentials Management vulnerability in Synology Ds107 Firmware and Ds213 Firmware
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) .
network
low complexity
synology CWE-255
critical
9.8
2018-07-13 CVE-2016-6553 Credentials Management vulnerability in Nuuo Nt-4040 Titan Firmware Nt404001.07.0000.00151120
Nuuo NT-4040 Titan, firmware NT-4040_01.07.0000.0015_1120, uses non-random default credentials of: admin:admin and localdisplay:111111.
network
low complexity
nuuo CWE-255
critical
9.8
2018-07-13 CVE-2016-6552 Credentials Management vulnerability in Greenpacket Dx-350 Firmware
Green Packet DX-350 uses non-random default credentials of: root:wimax.
network
low complexity
greenpacket CWE-255
critical
9.8
2018-07-13 CVE-2016-6551 Credentials Management vulnerability in Intelliantech products
Intellian Satellite TV antennas t-Series and v-Series, firmware version 1.07, uses non-random default credentials of: ftp/ftp or intellian:12345678.
network
low complexity
intelliantech CWE-255
critical
9.8
2018-07-11 CVE-2013-2951 Credentials Management vulnerability in IBM Websphere Portal
IBM WebSphere Portal 7.0.0.x and 8.0.0.x write passwords to a trace file when tracing is enabled for the Selfcare Portlet (Profile Management), which allows local users to obtain sensitive information by reading the file.
local
low complexity
ibm CWE-255
7.8
2018-05-29 CVE-2015-9240 Credentials Management vulnerability in Keystonejs Keystone
Due to a bug in the the default sign in functionality in the keystone node module before 0.3.16, incomplete email addresses could be matched.
network
low complexity
keystonejs CWE-255
7.5
2018-04-27 CVE-2013-5461 Credentials Management vulnerability in IBM products
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes.
network
low complexity
ibm CWE-255
8.8