Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
iOS MEDIUM 6.3
CVE-2013-1241

The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to caus…

Mitigation only
Fix from $1,600 2013-05-08
Unified Computing System Infrastructure And Unified Computing System Software HIGH 7.5
CVE-2013-1186

Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted auth…

Mitigation only
Fix from $1,950 2013-04-25
Imanager HIGH 10.0
CVE-2013-3268

Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

Fix: after 2.7
Fix from $1,950 2013-04-24
Activemq MEDIUM 6.4
CVE-2013-3060EPSS 6%

The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau…

Fix: after 5.7.0
Fix from $1,600 2013-04-21
Keystone MEDIUM 5.0
CVE-2013-0282

OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain i…

Fix: after 2012.2.4
Fix from $1,600 2013-04-12
Jboss Enterprise Portal Platform HIGH 7.5
CVE-2013-0314

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi…

Mitigation only
Fix from $1,950 2013-04-12
Adaptive Security Appliance Software HIGH 7.8
CVE-2013-1150

The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31),…

Mitigation only
Fix from $1,950 2013-04-11
Firewall Services Module Software HIGH 7.8
CVE-2013-1155

The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1…

Mitigation only
Fix from $1,950 2013-04-11
Backupbuddy HIGH 7.5
CVE-2013-2741

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, whic…

No fix yet
Fix from $1,950 2013-04-02
Backupbuddy HIGH 7.5
CVE-2013-2743

importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via …

No fix yet
Fix from $1,950 2013-04-02
Zenworks Configuration Management HIGH 10.0
CVE-2013-1080EPSS 77%

The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/js…

Mitigation only
Fix from $1,950 2013-03-29
Smarts Network Configuration Manager HIGH 9.3
CVE-2013-0935

EMC Smarts Network Configuration Manager (NCM) before 9.2 does not require authentication for all Java RMI method calls, which allows remote attacker…

Fix: after 9.1
Fix from $1,950 2013-03-28
Ga Login MEDIUM 6.8
CVE-2013-0258

The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers …

Patch available
Fix from $1,600 2013-03-27
Lotus Domino HIGH 8.5
CVE-2013-0487

The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration detai…

Mitigation only
Fix from $1,950 2013-03-27
Ubuntu Linux MEDIUM 6.8
CVE-2013-1865

OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot…

Mitigation only
Fix from $1,600 2013-03-22
Qpid MEDIUM 6.8
CVE-2012-4446

The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t…

Fix: after 0.20
Fix from $1,600 2013-03-14
Cxf MEDIUM 5.8
CVE-2012-5633EPSS 8%

The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu…

Fix: after 2.5.7
Fix from $1,600 2013-03-12
Cxf MEDIUM 5.0
CVE-2013-0239

Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att…

Fix: after 2.5.8
Fix from $1,600 2013-03-12
Eucalyptus MEDIUM 5.0
CVE-2012-4066

The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows at…

Fix: after 3.2.0
Fix from $1,600 2013-03-08
Chrome HIGH 7.5
CVE-2013-0910

Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization o…

Fix: after 25.0.1364.126
Fix from $1,950 2013-03-05
Unified Communications Manager HIGH 7.1
CVE-2013-1134

The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not req…

Mitigation only
Fix from $1,950 2013-02-27
Bigant Im Message Server MEDIUM 5.0
CVE-2012-6274EPSS 47%

BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under…

Mitigation only
Fix from $1,600 2013-02-24
Websphere Message Broker MEDIUM 5.0
CVE-2012-5952

IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor…

Mitigation only
Fix from $1,600 2013-02-20
San Volume Controller Software HIGH 7.5
CVE-2012-6354

The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain…

Mitigation only
Fix from $1,950 2013-02-19
Vcenter Server HIGH 10.0
CVE-2013-1405

VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 bef…

Mitigation only
Fix from $1,950 2013-02-15
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2012-0874EPSS 14%

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E…

Fix: after 5.3.0
Fix from $1,600 2013-02-05
Controllogix Controllers CRITICAL 9.8
CVE-2012-6437EPSS 8%

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…

Fix: after 1400
Fix from $2,300 2013-01-24
Movable Type HIGH 7.5
CVE-2013-0209EPSS 45%

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration fun…

Patch available
Fix from $1,950 2013-01-23
Firefox MEDIUM 5.0
CVE-2013-0759

Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a…

Fix: 2.15 / 10.0.12+
Fix from $1,600 2013-01-13
Coldfusion CRITICAL 9.8
CVE-2013-0625 KEVEPSS 94%

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbi…

Mitigation only
Fix from $2,300 2013-01-09