Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Elinks MEDIUM 5.1
CVE-2012-4545

The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotia…

Mitigation only
Fix from $1,600 2013-01-03
Oplynx HIGH 7.5
CVE-2012-4688

The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser…

Fix: after 2.01.8
Fix from $1,950 2012-12-31
Privileged User Manager MEDIUM 6.4
CVE-2012-5930EPSS 7%

The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for…

No fix yet
Fix from $1,600 2012-12-24
H.264 Hi3510\/11\/12 Ip Camera HIGH 10.0
CVE-2012-3002

The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or…

Mitigation only
Fix from $1,950 2012-12-21
Freesshd HIGH 9.3
CVE-2012-6066EPSS 40%

freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client w…

Fix: after 1.2.6
Fix from $1,950 2012-12-04
Freeftpd HIGH 10.0
CVE-2012-6067

freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH cl…

Fix: after 1.0.11
Fix from $1,950 2012-12-04
Tectia Server HIGH 9.3
CVE-2012-5975EPSS 36%

The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2…

No fix yet
Fix from $1,950 2012-12-04
It Operations Intelligence HIGH 9.3
CVE-2012-4614

The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which all…

Fix: after 9.0
Fix from $1,950 2012-11-27
Ar Web Content Manager MEDIUM 5.0
CVE-2012-2437

cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via …

No fix yet
Fix from $1,600 2012-11-26
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-4085

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, …

Fix: after 5.2.0
Fix from $1,600 2012-11-23
Sinapsi Firmware HIGH 10.0
CVE-2012-5864

These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within t…

Fix: after 2.0.2870
Fix from $1,950 2012-11-23
Websphere Datapower Xc10 Appliance HIGH 7.8
CVE-2012-5758

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int…

Mitigation only
Fix from $1,950 2012-11-23
Tomcat MEDIUM 5.0
CVE-2012-5886EPSS 9%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…

Mitigation only
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5887EPSS 12%

The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly…

Fix: 5.5.36 / 6.0.36+
Fix from $1,600 2012-11-17
Rsa Data Protection Manager Appliance MEDIUM 6.9
CVE-2012-4613

EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user accou…

Mitigation only
Fix from $1,600 2012-11-16
Kintai Kanri MEDIUM 5.5
CVE-2012-4021

MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accoun…

Fix: after 4.0.9
Fix from $1,600 2012-11-08
Tivoli Federated Identity Manager MEDIUM 5.0
CVE-2012-3315

The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Busin…

Fix: after 6.2.2
Fix from $1,600 2012-11-08
Adaptive Security Appliance Software HIGH 7.1
CVE-2012-4659

The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Modul…

Mitigation only
Fix from $1,950 2012-10-29
Axis2 MEDIUM 5.8
CVE-2012-4418EPSS 6%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

No fix yet
Fix from $1,600 2012-10-09
Axis2 MEDIUM 6.4
CVE-2012-5351EPSS 5%

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…

Mitigation only
Fix from $1,600 2012-10-09
Java Open Single Sign On Project Home MEDIUM 5.8
CVE-2012-5352

Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a S…

Mitigation only
Fix from $1,600 2012-10-09
Openathens Service Provider MEDIUM 5.8
CVE-2012-5353

Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature el…

Mitigation only
Fix from $1,600 2012-10-09
Keystone HIGH 7.5
CVE-2012-4456

The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-…

Fix: 2012.1.2+
Fix from $1,950 2012-10-09
Lotus Notes Traveler MEDIUM 6.8
CVE-2012-5309

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it…

No fix yet
Fix from $1,600 2012-10-08
Nextbbs HIGH 7.5
CVE-2012-1602

user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.

No fix yet
Fix from $1,950 2012-10-01
Condor MEDIUM 6.4
CVE-2012-3492

The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories eve…

Mitigation only
Fix from $1,600 2012-09-28
Rsa Authentication Agent HIGH 8.5
CVE-2012-2287

The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an…

Mitigation only
Fix from $1,950 2012-09-25
Database Server MEDIUM 6.4
CVE-2012-3137EPSS 31%

The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtai…

Patch available
Fix from $1,600 2012-09-21
Mac Os X MEDIUM 5.0
CVE-2012-3721

Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows at…

Fix: after 10.7.4
Fix from $1,600 2012-09-20
Nx Web Companion MEDIUM 6.8
CVE-2012-5003

nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote a…

Fix: after 3.5.0-2
Fix from $1,600 2012-09-19