Show filters
182 Total Results
Displaying 161-170 of 182
Sort by:
Attacker Value
Unknown
CVE-2020-10244
Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JPaseto before 0.3.0 generates weak hashes when using v2.local tokens.
0
Attacker Value
Unknown
CVE-2020-9476
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
0
Attacker Value
Unknown
CVE-2019-18863
Disclosure Date: March 02, 2020 (last updated February 21, 2025)
A key length vulnerability in the implementation of the SRTP 128-bit key on Mitel 6800 and 6900 SIP series phones, versions 5.1.0.2051 SP2 and earlier, could allow an attacker to launch a man-in-the-middle attack when SRTP is used in a call. A successful exploit may allow the attacker to intercept sensitive information.
0
Attacker Value
Unknown
CVE-2019-4557
Disclosure Date: February 24, 2020 (last updated February 21, 2025)
IBM Qradar Advisor 1.1 through 2.5 with Watson uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 166206.
0
Attacker Value
Unknown
CVE-2013-7287
Disclosure Date: February 13, 2020 (last updated February 21, 2025)
MobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
0
Attacker Value
Unknown
CVE-2013-7286
Disclosure Date: February 12, 2020 (last updated February 21, 2025)
MobileIron VSP < 5.9.1 and Sentry < 5.0 has a weak password obfuscation algorithm
0
Attacker Value
Unknown
CVE-2019-13163
Disclosure Date: February 07, 2020 (last updated February 21, 2025)
The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions, Interstage Information Integrator V11 and other versions, Interstage Job Workload Server V8, Interstage List Works V10 and other versions, Interstage Studio V12 and other versions, Interstage Web Server Express V11, Linkexpress V5, Safeauthor V3, ServerView Resource Orchestrator V3, Systemwalker Cloud Business Service Management V1, Systemwalker Desktop Keeper V15, Systemwalker Desktop Patrol V15, Systemwalker IT Change Manager V14, Systemwalker Operation Manager V16 and other versions, Systemwalker Runbook Automation V15 and other versions, Systemwalker Security Control V1, and Systemwalker Software Configuration Manager V15.
0
Attacker Value
Unknown
CVE-2011-3629
Disclosure Date: February 04, 2020 (last updated February 21, 2025)
Joomla! core 1.7.1 allows information disclosure due to weak encryption
0
Attacker Value
Unknown
Session key exposure through session list in Django User Sessions
Disclosure Date: January 24, 2020 (last updated February 21, 2025)
In Django User Sessions (django-user-sessions) before 1.7.1, the views provided allow users to terminate specific sessions. The session key is used to identify sessions, and thus included in the rendered HTML. In itself this is not a problem. However if the website has an XSS vulnerability, the session key could be extracted by the attacker and a session takeover could happen.
0
Attacker Value
Unknown
CVE-2020-6966
Disclosure Date: January 24, 2020 (last updated February 21, 2025)
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain remote code execution of devices on the network.
0