Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Dotclear MEDIUM 5.8
CVE-2014-3781

The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa…

Fix: after 2.6.2
Fix from $1,600 2014-06-11
TYPO3 MEDIUM 5.8
CVE-2014-3944

The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2014-06-03
Libpam Pgsql MEDIUM 5.0
CVE-2013-0191

libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass…

Patch available
Fix from $1,600 2014-06-03
Openstack MEDIUM 5.0
CVE-2013-6470

The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt…

Mitigation only
Fix from $1,600 2014-06-02
Vdi In A Box HIGH 7.5
CVE-2014-3780

Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspe…

Mitigation only
Fix from $1,950 2014-05-30
Bitrix E Store Module HIGH 7.5
CVE-2013-6788

The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for r…

Fix: after 14.0.0
Fix from $1,950 2014-05-30
Ga Login MEDIUM 5.0
CVE-2013-4178

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replay…

Mitigation only
Fix from $1,600 2014-05-29
Email Firewall MEDIUM 5.0
CVE-2012-6452

Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests dependi…

Fix: after 6.5.0
Fix from $1,600 2014-05-27
Moodle MEDIUM 6.8
CVE-2014-0214

login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token wi…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Cloudstack MEDIUM 5.0
CVE-2013-2756EPSS 6%

Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa…

Patch available
Fix from $1,600 2014-05-23
Faceid F810 Firmware HIGH 8.3
CVE-2014-2938

Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data v…

Fix: after 1.007.109
Fix from $1,950 2014-05-22
Openvas Manager HIGH 7.5
CVE-2013-6765EPSS 7%

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands …

Mitigation only
Fix from $1,950 2014-05-19
Openvas Administrator HIGH 7.5
CVE-2013-6766

OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP com…

Mitigation only
Fix from $1,950 2014-05-19
Exceed Ondemand MEDIUM 6.8
CVE-2013-6806

OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a cr…

Mitigation only
Fix from $1,600 2014-05-19
Tomato MEDIUM 6.8
CVE-2013-7379

The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote at…

Fix: after 0.0.5
Fix from $1,600 2014-05-16
Rsa Netwitness HIGH 7.6
CVE-2014-0643

EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a …

Fix: 9.8.5.19 / 10.2.4+
Fix from $1,950 2014-05-16
Dovecot MEDIUM 5.0
CVE-2014-3430

Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attac…

Patch available
Fix from $1,600 2014-05-14
Horizon MEDIUM 5.5
CVE-2013-4471

The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w…

Fix: 2013.2+
Fix from $1,600 2014-05-14
Drupalauth HIGH 7.5
CVE-2013-4552

lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via…

Fix: after 1.2.1
Fix from $1,950 2014-05-13
GitLab MEDIUM 6.8
CVE-2013-4580

GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impe…

Fix: after 5.4.1
Fix from $1,600 2014-05-12
Dir 826l Wireless N600 Cloud Router Firmware HIGH 9.3
CVE-2013-4772

D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a d…

No fix yet
Fix from $1,950 2014-05-12
Foreman MEDIUM 6.8
CVE-2014-0090

Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie.

Fix: after 1.4.1
Fix from $1,600 2014-05-08
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2014-2181

Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demo…

Mitigation only
Fix from $1,600 2014-05-07
Enterprise Backup HIGH 7.5
CVE-2014-3139

recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to …

No fix yet
Fix from $1,950 2014-05-02
Ubercart MEDIUM 6.8
CVE-2013-7302

Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers a…

Patch available
Fix from $1,600 2014-04-29
Codesys Runtime System HIGH 9.3
CVE-2014-0760

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented acc…

Mitigation only
Fix from $1,950 2014-04-25
Softmotion HIGH 9.3
CVE-2014-0769

The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication…

Mitigation only
Fix from $1,950 2014-04-25
Openshift HIGH 7.5
CVE-2014-0188

The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot…

Fix: after 2.0.5
Fix from $1,950 2014-04-24
iOS MEDIUM 5.0
CVE-2012-4658

The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage…

Fix: after 15.1
Fix from $1,600 2014-04-23
iOS MEDIUM 6.4
CVE-2012-5032

The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows re…

Fix: after 15.1
Fix from $1,600 2014-04-23