The AES encryption module 7.x-1.4 for Drupal leaves certain debugging code enabled in release, which records the plaintext password of the last logged-in user and allows remote attackers to gain privileges as that user.
https://exchange.xforce.ibmcloud.com/vulnerabilities/65112
http://www.securityfocus.com/bid/46116
http://secunia.com/advisories/43185