Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Video Surveillance Operations Manager MEDIUM 6.8
CVE-2014-0674

Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2014-01-24
Chrome HIGH 7.5
CVE-2013-6643

The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on…

Fix: 32.0.1700.76 / 32.0.1700.77+
Fix from $1,950 2014-01-16
Raven X Ev Do Firmware HIGH 10.0
CVE-2013-2820

The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay …

Mitigation only
Fix from $1,950 2014-01-15
Endpoint Protection HIGH 7.4
CVE-2013-5009

The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business E…

Fix: after 11.0.7.3
Fix from $1,950 2014-01-10
Ns Wir150ne Firmware HIGH 10.0
CVE-2013-7282EPSS 10%

The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows r…

Mitigation only
Fix from $1,950 2014-01-10
Hotbox Router Firmware MEDIUM 5.8
CVE-2013-5038

The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously be…

No fix yet
Fix from $1,600 2013-12-30
Garoon MEDIUM 5.8
CVE-2013-6006

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

Mitigation only
Fix from $1,600 2013-12-28
Debian Linux MEDIUM 5.0
CVE-2013-6890EPSS 9%

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in…

Mitigation only
Fix from $1,600 2013-12-23
Ios Xe MEDIUM 5.4
CVE-2013-6979

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, w…

Mitigation only
Fix from $1,600 2013-12-23
Subscription Asset Manager HIGH 9.3
CVE-2013-6439

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a sche…

No fix yet
Fix from $1,950 2013-12-23
Zabbix MEDIUM 5.0
CVE-2013-1364

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

Fix: after 1.8.15
Fix from $1,600 2013-12-14
Network Interface Router MEDIUM 5.0
CVE-2013-7093

SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vecto…

Mitigation only
Fix from $1,600 2013-12-13
Dovecot MEDIUM 5.8
CVE-2013-6171

checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentica…

Fix: after 2.2.6
Fix from $1,600 2013-12-09
Sinamics S\/g Family Firmware HIGH 10.0
CVE-2013-6920

Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers…

Fix: after 4.6
Fix from $1,950 2013-12-07
Chrome MEDIUM 6.8
CVE-2013-6634

The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an i…

Fix: after 31.0.1650.62
Fix from $1,600 2013-12-07
Adaptive Server Enterprise HIGH 8.5
CVE-2013-6859

SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properl…

Mitigation only
Fix from $1,950 2013-11-23
Mail Secure MEDIUM 6.4
CVE-2013-6828

admin/management.html in PineApp Mail-SeCure allows remote attackers to bypass authentication and perform a sys_usermng operation via the it paramete…

Mitigation only
Fix from $1,600 2013-11-20
Salt MEDIUM 6.0
CVE-2013-4435

Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricte…

Patch available
Fix from $1,600 2013-11-05
Zenworks Configuration Management MEDIUM 6.8
CVE-2013-6347

Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via uns…

Fix: after 11.2.3
Fix from $1,600 2013-11-02
Junos HIGH 8.5
CVE-2013-6012

Juniper Junos 12.1X44 before 12.1.X44-D20 and 12.1X45 before 12.1X45-D15, when the no-validate option is enabled, does not properly handle configurat…

Mitigation only
Fix from $1,950 2013-10-28
Puppet Enterprise MEDIUM 5.0
CVE-2013-4965

Puppet Enterprise before 3.1.0 does not properly restrict the number of authentication attempts by a console account, which makes it easier for remot…

Fix: after 3.0.1
Fix from $1,600 2013-10-25
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5531

Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and cre…

Mitigation only
Fix from $1,600 2013-10-25
Imc Service Operation Management Software Module HIGH 7.5
CVE-2013-4824EPSS 24%

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers t…

Mitigation only
Fix from $1,950 2013-10-13
Adaptive Security Appliance Software HIGH 10.0
CVE-2013-5511

The Adaptive Security Device Management (ASDM) remote-management feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), …

Mitigation only
Fix from $1,950 2013-10-13
Rt N10e Firmware MEDIUM 6.1
CVE-2013-3610

qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discove…

Fix: after 2.0.0.24
Fix from $1,600 2013-10-05
Mac Os X MEDIUM 6.6
CVE-2013-5163

Directory Services in Apple Mac OS X before 10.8.5 Supplemental Update allows local users to bypass password-based authentication and modify arbitrar…

Fix: after 10.8.5
Fix from $1,600 2013-10-04
Scalance X 200 Series Firmware HIGH 10.0
CVE-2013-5944

The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not pro…

Fix: after 5.0.1
Fix from $1,950 2013-10-03
Video Surveillance Operations Manager MEDIUM 5.0
CVE-2013-3417

The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attacke…

Mitigation only
Fix from $1,600 2013-09-30
Open Xchange Appsuite HIGH 7.5
CVE-2013-5200

The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 …

No fix yet
Fix from $1,950 2013-09-25
Unified Computing System HIGH 8.5
CVE-2012-4078

The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote …

Mitigation only
Fix from $1,950 2013-09-24