Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Iphone Os MEDIUM 6.8
CVE-2014-1295

Secure Transport in Apple iOS before 7.1.1, Apple OS X 10.8.x and 10.9.x through 10.9.2, and Apple TV before 6.1.1 does not ensure that a server's X.…

Fix: after 7.1
Fix from $1,600 2014-04-23
Cubecart MEDIUM 6.8
CVE-2014-2341EPSS 6%

Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

Fix: after 5.2.8
Fix from $1,600 2014-04-22
Remote Service Manager MEDIUM 6.8
CVE-2014-1984

Session fixation vulnerability in the management screen in Cybozu Remote Service Manager through 2.3.0 and 3.x before 3.1.1 allows remote attackers t…

Fix: after 3.1.0
Fix from $1,600 2014-04-19
Strongswan MEDIUM 6.4
CVE-2014-2338

IKEv2 in strongSwan 4.0.7 before 5.1.3 allows remote attackers to bypass authentication by rekeying an IKE_SA during (1) initiation or (2) re-authent…

Mitigation only
Fix from $1,600 2014-04-16
Curl MEDIUM 6.4
CVE-2014-0138EPSS 5%

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8)…

Mitigation only
Fix from $1,600 2014-04-15
Keystone HIGH 7.8
CVE-2014-2828

The V3 API in OpenStack Identity (Keystone) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2014-04-15
Misecuremessages MEDIUM 5.0
CVE-2014-0357

Amtelco miSecureMessages allows remote attackers to read the messages of arbitrary users via an XML request containing a valid license key and a modi…

Mitigation only
Fix from $1,600 2014-04-15
N300 Netusb Nbg 419n Firmware MEDIUM 6.1
CVE-2014-0353

The ZyXEL Wireless N300 NetUSB NBG-419N router with firmware 1.00(BFQ.6)C0 allows remote attackers to bypass authentication by using %2F sequences in…

Mitigation only
Fix from $1,600 2014-04-15
Software Deployment Manager MEDIUM 5.0
CVE-2013-7366

The SAP Software Deployment Manager (SDM), in certain unspecified conditions, allows remote attackers to cause a denial of service via vectors relate…

No fix yet
Fix from $1,600 2014-04-10
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-2128

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47, 8.3 before 8.3(2.40), 8.4 before 8.4(7.3), 8.6 be…

Mitigation only
Fix from $1,600 2014-04-10
WordPress MEDIUM 6.4
CVE-2014-0166EPSS 9%

The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the va…

Fix: after 3.7.1
Fix from $1,600 2014-04-10
Vplex Geosynchrony HIGH 7.5
CVE-2014-0635

Session fixation vulnerability in EMC VPLEX GeoSynchrony 4.x and 5.x before 5.3 allows remote attackers to hijack web sessions via unspecified vector…

Mitigation only
Fix from $1,950 2014-04-01
Img646bd Firmware HIGH 10.0
CVE-2014-1982EPSS 10%

The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firmware 2.4, and iMG646BD firmwa…

Mitigation only
Fix from $1,950 2014-03-31
389 Directory Server MEDIUM 6.5
CVE-2014-0132

The SASL authentication functionality in 389 Directory Server before 1.2.11.26 allows remote authenticated users to connect as an arbitrary user and …

Fix: after 1.2.11.25
Fix from $1,600 2014-03-18
Owncloud MEDIUM 6.8
CVE-2014-2047

Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote att…

Fix: after 6.0.1
Fix from $1,600 2014-03-14
Puppet Enterprise MEDIUM 6.4
CVE-2013-4966

The master external node classification script in Puppet Enterprise before 3.2.0 does not verify the identity of consoles, which allows remote attack…

Fix: after 3.1.1
Fix from $1,600 2014-03-09
Fi8919w Firmware HIGH 7.8
CVE-2014-1911

The Foscam FI8910W camera with firmware before 11.37.2.55 allows remote attackers to obtain sensitive video and image data via a blank username and p…

Fix: after 11.37.2.54
Fix from $1,950 2014-03-06
Enterprise Administrator HIGH 10.0
CVE-2014-2075

TIBCO Enterprise Administrator 1.0.0 and Enterprise Administrator SDK 1.0.0 do not properly enforce administrative authentication requirements, which…

Mitigation only
Fix from $1,950 2014-02-27
Unified Communications Manager MEDIUM 5.0
CVE-2014-0743

The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote atta…

Fix: after 10.0
Fix from $1,600 2014-02-27
Unified Communications Manager MEDIUM 5.0
CVE-2014-0733

The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce aut…

Fix: after 10.0
Fix from $1,600 2014-02-20
Unified Communications Manager MEDIUM 5.0
CVE-2014-0732

The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enfor…

Fix: after 10.0
Fix from $1,600 2014-02-20
Jboss Operations Network MEDIUM 5.8
CVE-2012-0062

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Jboss Operations Network MEDIUM 5.8
CVE-2012-1100

Red Hat JBoss Operations Network (JON) 3.0.x before 3.0.1, 2.4.2, and earlier, when LDAP authentication is enabled and the LDAP bind account credenti…

Fix: after 2.4.1
Fix from $1,600 2014-02-14
Unified Communications Manager MEDIUM 5.0
CVE-2014-0722

The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-02-13
Unified Communications Manager MEDIUM 5.0
CVE-2014-0725

Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2014-02-13
Opensuse MEDIUM 5.0
CVE-2011-4091

The libobby server in inc/server.hpp in libnet6 (aka net6) before 1.3.14 does not perform authentication before checking the user name, which allows …

Fix: after 1.3.13
Fix from $1,600 2014-02-10
Gatehouse HIGH 10.0
CVE-2013-6035

The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE…

Mitigation only
Fix from $1,950 2014-02-04
Swc 9100 HIGH 7.8
CVE-2013-7183

cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or…

Mitigation only
Fix from $1,950 2014-02-04
Centralauth Extension HIGH 7.5
CVE-2013-4304

The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in…

Patch available
Fix from $1,950 2014-01-26
Burden CRITICAL 9.8
CVE-2013-7137EPSS 16%

The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting t…

Fix: 1.8.1+
Fix from $2,300 2014-01-26