Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Img Pals Photo Host MEDIUM 6.4
CVE-2012-4926

approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via t…

No fix yet
Fix from $1,600 2012-09-15
Webmin MEDIUM 5.0
CVE-2012-2983EPSS 20%

file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote…

Fix: after 1.590
Fix from $1,600 2012-09-11
Owncloud Server HIGH 7.5
CVE-2012-4392

index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_t…

Patch available
Fix from $1,950 2012-09-05
Packetfence MEDIUM 5.0
CVE-2012-4741

The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment ext…

Fix: after 3.2.0
Fix from $1,600 2012-08-31
Cloud Tiering Appliance Virtual Edition MEDIUM 6.8
CVE-2012-2285

EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows rem…

Fix: after 9.0
Fix from $1,600 2012-08-29
Qpid MEDIUM 5.0
CVE-2012-3467EPSS 6%

Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo…

Fix: after 0.16
Fix from $1,600 2012-08-27
Condor HIGH 10.0
CVE-2012-3416EPSS 5%

Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by con…

Fix: after 7.8.1
Fix from $1,950 2012-08-25
Email And Web Security HIGH 7.5
CVE-2012-4595

McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack…

Mitigation only
Fix from $1,950 2012-08-22
Smartfilter Administration HIGH 10.0
CVE-2012-4599

McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBo…

Fix: after 4.2.1
Fix from $1,950 2012-08-22
Firewall Reporter HIGH 7.5
CVE-2011-5100

The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obt…

Fix: after 5.1.0.6
Fix from $1,950 2012-08-22
Email And Web Security MEDIUM 6.8
CVE-2012-4581

McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl…

Mitigation only
Fix from $1,600 2012-08-22
Linuxshield MEDIUM 6.5
CVE-2009-5116

McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin acces…

Fix: after 1.5.1
Fix from $1,600 2012-08-22
Libsoup MEDIUM 5.0
CVE-2012-2132

libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-08-20
Niagara Ax MEDIUM 5.0
CVE-2012-3024

Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authe…

Fix: after 3.6
Fix from $1,600 2012-08-16
Ushahidi Platform MEDIUM 6.4
CVE-2012-3472

The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows …

Fix: after 2.4.1
Fix from $1,600 2012-08-12
Ushahidi Platform MEDIUM 6.4
CVE-2012-3473

The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allow…

Fix: after 2.4.1
Fix from $1,600 2012-08-12
Breakingpoint Storm Appliance Ctm MEDIUM 5.0
CVE-2012-2963

The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/B…

Fix: after 2.0
Fix from $1,600 2012-08-12
Rails MEDIUM 5.0
CVE-2012-3424

The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7…

Mitigation only
Fix from $1,600 2012-08-08
Scrutinizer MEDIUM 5.0
CVE-2012-2626EPSS 44%

cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…

Fix: 9.5.0+
Fix from $1,600 2012-07-31
Airdroid MEDIUM 5.0
CVE-2012-3884

AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to…

No fix yet
Fix from $1,600 2012-07-26
Airdroid HIGH 7.5
CVE-2012-3885

The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain ac…

No fix yet
Fix from $1,950 2012-07-26
Viewvc MEDIUM 5.0
CVE-2012-3356

The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote att…

Fix: after 1.1.14
Fix from $1,600 2012-07-22
Smc8024l2 Switch HIGH 10.0
CVE-2012-2974

The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request …

Mitigation only
Fix from $1,950 2012-07-19
Debian Linux MEDIUM 5.0
CVE-2012-2351

The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, whic…

Fix: after 1.4.1
Fix from $1,600 2012-07-12
Message Filter MEDIUM 5.4
CVE-2012-0301

Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspeci…

Fix: after 6.3
Fix from $1,600 2012-07-05
Access Manager Agent MEDIUM 6.8
CVE-2012-2281

EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might all…

Mitigation only
Fix from $1,600 2012-07-05
Mantisbt HIGH 7.5
CVE-2012-1123

The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a n…

Fix: after 1.2.8
Fix from $1,950 2012-06-29
Strongswan HIGH 7.5
CVE-2012-2388

The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "R…

Mitigation only
Fix from $1,950 2012-06-27
MySQL MEDIUM 5.1
CVE-2012-2122EPSS 97%

sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12…

Patch available
Fix from $1,600 2012-06-26
Wyse Device Manager HIGH 7.5
CVE-2009-0695EPSS 69%

hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access…

No fix yet
Fix from $1,950 2012-06-19