Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Django MEDIUM 5.0
CVE-2013-1443

The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attack…

Patch available
Fix from $1,600 2013-09-23
Zimbra Collaboration Suite MEDIUM 6.8
CVE-2013-5119

Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_…

Fix: after 6.0.16
Fix from $1,600 2013-09-23
Prime Central For Hosted Collaboration Solution Assurance HIGH 7.8
CVE-2013-3473

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of …

Fix: after 9.1
Fix from $1,950 2013-09-20
Dvr0404hd A HIGH 7.8
CVE-2013-3613EPSS 7%

Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a repl…

Mitigation only
Fix from $1,950 2013-09-17
Rational Requirements Composer MEDIUM 5.4
CVE-2013-3039

IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.

Fix: after 4.0.3
Fix from $1,600 2013-09-12
Pan Os HIGH 10.0
CVE-2012-6603

The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authe…

Fix: after 3.1.11
Fix from $1,950 2013-08-31
Secure Access Control Server HIGH 9.3
CVE-2013-3466EPSS 5%

The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled,…

Fix: after 4.2.1.15.10
Fix from $1,950 2013-08-29
Smart Viewer HIGH 7.6
CVE-2013-3586EPSS 11%

Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.

Mitigation only
Fix from $1,950 2013-08-28
Puppet Enterprise MEDIUM 6.9
CVE-2013-4958

Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended wor…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Websphere Commerce MEDIUM 5.8
CVE-2013-2993

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allo…

Mitigation only
Fix from $1,600 2013-08-01
Satellite MEDIUM 5.0
CVE-2013-2056

The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al…

Mitigation only
Fix from $1,600 2013-07-31
Video Surveillance Manager HIGH 9.0
CVE-2013-3430EPSS 8%

Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspe…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Video Surveillance Manager HIGH 7.8
CVE-2013-3431EPSS 9%

Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attacker…

Fix: after 6.3.3
Fix from $1,950 2013-07-25
Cybozu Office MEDIUM 5.8
CVE-2013-3656

Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of …

Fix: after 9.1.0
Fix from $1,600 2013-07-20
Wireless Network Extender MEDIUM 6.2
CVE-2013-4874

The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a c…

Mitigation only
Fix from $1,600 2013-07-18
Wireless Network Extender MEDIUM 6.2
CVE-2013-4875

The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and …

Mitigation only
Fix from $1,600 2013-07-18
Bmc HIGH 10.0
CVE-2013-4782EPSS 26%

The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka c…

Mitigation only
Fix from $1,950 2013-07-08
Idrac6 Bmc HIGH 10.0
CVE-2013-4783

The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass…

Mitigation only
Fix from $1,950 2013-07-08
Integrated Lights Out Bmc HIGH 10.0
CVE-2013-4784EPSS 50%

The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using c…

Mitigation only
Fix from $1,950 2013-07-08
Wixfmr 111 HIGH 7.1
CVE-2013-3581

ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information v…

Mitigation only
Fix from $1,950 2013-07-02
Wixfmr 111 HIGH 9.3
CVE-2013-4731

ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via…

No fix yet
Fix from $1,950 2013-06-30
Tomcat MEDIUM 6.8
CVE-2013-2067EPSS 7%

java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor…

Patch available
Fix from $1,600 2013-06-01
Nx Os MEDIUM 5.0
CVE-2013-1209

The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Ne…

Mitigation only
Fix from $1,600 2013-05-29
Nx Os MEDIUM 5.0
CVE-2013-1211

Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communica…

Mitigation only
Fix from $1,600 2013-05-29
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.0
CVE-2013-2954

The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the num…

Mitigation only
Fix from $1,600 2013-05-27
Keystone MEDIUM 6.0
CVE-2013-2059

OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token w…

No fix yet
Fix from $1,600 2013-05-21
Unified Communications Manager MEDIUM 5.0
CVE-2013-1188

Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2013-05-16
Secure Access Control System MEDIUM 6.8
CVE-2013-1200

Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2013-05-16
.net Framework HIGH 7.5
CVE-2013-1337EPSS 21%

Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication i…

Mitigation only
Fix from $1,950 2013-05-15
Documentum Records Manager MEDIUM 5.8
CVE-2013-0937

Session fixation vulnerability in EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Docum…

Mitigation only
Fix from $1,600 2013-05-10