CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
58142 | CVE-2012-4899 | Candidate | WellinTech KingView 6.5.3 and earlier uses a weak password-hashing algorithm, which makes it easier for local users to discover credentials by reading an unspecified file. | Assigned (20120912) | None (candidate not yet proposed) | View | |
62773 | CVE-2013-2826 | Candidate | WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attackers to bypass intended access restrictions and discover credentials via a crafted packet to TCP port 8130. | Assigned (20130411) | None (candidate not yet proposed) | View | |
55220 | CVE-2012-1977 | Candidate | WellinTech KingSCADA 3.0 uses a cleartext base64 format for storage of passwords in user.db, which allows context-dependent attackers to obtain sensitive information by reading this file. | Assigned (20120330) | None (candidate not yet proposed) | View | |
55802 | CVE-2012-2559 | Candidate | WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678. | Assigned (20120509) | None (candidate not yet proposed) | View | |
58598 | CVE-2012-5355 | Candidate | welcome.py in xdiagnose before 2.5.2ubuntu0.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp. | Assigned (20121010) | None (candidate not yet proposed) | View |
Page 226 of 20943, showing 5 records out of 104715 total, starting on record 1126, ending on 1130