Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Satellite MEDIUM 5.0
CVE-2012-1145

spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga…

Mitigation only
Fix from $1,600 2012-06-16
Network Sentry Appliance Software MEDIUM 5.0
CVE-2012-2606

The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display …

Fix: after 5.3
Fix from $1,600 2012-06-13
Grboard MEDIUM 6.4
CVE-2011-5090

GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modif…

No fix yet
Fix from $1,600 2012-05-24
Mobiletrack HIGH 7.6
CVE-2012-2562

The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute …

Fix: after 2.3.7
Fix from $1,950 2012-05-22
Qpid HIGH 7.5
CVE-2011-3620EPSS 5%

Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…

Mitigation only
Fix from $1,950 2012-05-03
Intrusion Prevention System MEDIUM 5.0
CVE-2011-4022

The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and ma…

Mitigation only
Fix from $1,600 2012-05-03
Small Business Ip Phone Firmware MEDIUM 5.0
CVE-2012-0333

Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remot…

Fix: after 7.4.9
Fix from $1,600 2012-05-02
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2012-0335

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attemp…

Mitigation only
Fix from $1,600 2012-05-02
Open Source MEDIUM 6.5
CVE-2012-2414

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk B…

Patch available
Fix from $1,600 2012-04-30
Scalance S Firmware HIGH 10.0
CVE-2012-1799EPSS 5%

The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate …

Fix: after 2.3.0
Fix from $1,950 2012-04-18
H0 Ecom HIGH 7.5
CVE-2012-1806

The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password …

Mitigation only
Fix from $1,950 2012-04-13
H0 Ecom HIGH 10.0
CVE-2012-1808

The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not r…

Mitigation only
Fix from $1,950 2012-04-13
Ajaxplorer HIGH 7.5
CVE-2012-1840

AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login a…

Patch available
Fix from $1,950 2012-03-22
Elo Gs24m Switch MEDIUM 5.0
CVE-2012-1838

The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext cr…

Mitigation only
Fix from $1,600 2012-03-22
Envision HIGH 7.9
CVE-2012-0400

EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote att…

Mitigation only
Fix from $1,950 2012-03-20
Easyvista MEDIUM 5.0
CVE-2012-1256

The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account p…

Fix: after 2010
Fix from $1,600 2012-02-22
Advantech Webaccess MEDIUM 5.0
CVE-2012-0239

uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an admin…

Fix: after 6.0
Fix from $1,600 2012-02-21
Advantech Webaccess HIGH 10.0
CVE-2012-0240

GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbit…

Fix: after 6.0
Fix from $1,950 2012-02-21
Wincc Flexible HIGH 9.3
CVE-2011-4508

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C…

Mitigation only
Fix from $1,950 2012-02-03
Wincc Flexible HIGH 10.0
CVE-2011-4514

The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels…

Mitigation only
Fix from $1,950 2012-02-03
Mac Os X HIGH 7.2
CVE-2011-3463

WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera…

Mitigation only
Fix from $1,950 2012-02-02
Modicon Quantum Plc CRITICAL 9.8
CVE-2012-0931

Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a d…

Mitigation only
Fix from $2,300 2012-01-28
Pcanywhere HIGH 10.0
CVE-2011-3478EPSS 39%

The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 1…

Mitigation only
Fix from $1,950 2012-01-25
Kcheckpass MEDIUM 6.9
CVE-2011-5054

kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi…

Mitigation only
Fix from $1,600 2012-01-06
Wifi Protected Setup Protocol MEDIUM 5.8
CVE-2011-5053

The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed …

Mitigation only
Fix from $1,600 2012-01-06
Splunk HIGH 9.3
CVE-2011-4644EPSS 8%

Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally doe…

Fix: after 4.2.5
Fix from $1,950 2012-01-03
Bugzilla MEDIUM 6.8
CVE-2011-3667

The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, …

Mitigation only
Fix from $1,600 2012-01-02
Imapd HIGH 7.5
CVE-2011-3372

imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO U…

Fix: after 2.4.11
Fix from $1,950 2011-12-24
Quantum Ethernet Module 140noe77100 HIGH 10.0
CVE-2011-4860

The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates th…

Fix: after 5.0
Fix from $1,950 2011-12-17
One Click Orgs HIGH 7.5
CVE-2011-4677

One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obta…

Fix: after 1.2.2
Fix from $1,950 2011-12-06