Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Web Studio HIGH 10.0
CVE-2011-4051EPSS 69%

CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows re…

Patch available
Fix from $1,950 2011-12-05
Ts3100 Tape Library Firmware MEDIUM 6.8
CVE-2011-1372

The Web User Interface on the IBM TS3100 and TS3200 tape libraries with firmware before A.60 allows remote attackers to bypass authentication and obt…

Mitigation only
Fix from $1,600 2011-11-28
Opengear Console Server Firmware HIGH 7.5
CVE-2011-3997

Opengear console servers with firmware before 2.2.1 allow remote attackers to bypass authentication, and modify settings or access connected equipmen…

Fix: after 2.1.0u7
Fix from $1,950 2011-11-09
A Form MEDIUM 5.5
CVE-2011-2676

The A-Form and A-Form bamboo before 1.3.6 and 2.x before 2.0.3, and A-Form PC and PC/Mobile before 3.1, plug-ins for Movable Type do not require admi…

Fix: after 3.0
Fix from $1,600 2011-11-03
Aims HIGH 10.0
CVE-2011-4214

OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges vi…

Mitigation only
Fix from $1,950 2011-11-01
Firewall Services Module Software HIGH 7.8
CVE-2011-3297

Cisco Firewall Services Module (aka FWSM) 3.1 before 3.1(21), 3.2 before 3.2(22), 4.0 before 4.0(16), and 4.1 before 4.1(7), when certain authenticat…

Mitigation only
Fix from $1,950 2011-10-06
Adaptive Security Appliance Software HIGH 7.9
CVE-2011-3298

Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 be…

Mitigation only
Fix from $1,950 2011-10-06
Fast Cgi HIGH 7.5
CVE-2011-2766EPSS 7%

The FCGI (aka Fast CGI) module 0.70 through 0.73 for Perl, as used by CGI::Fast, uses environment variable values from one request during processing …

Fix: after 0.73
Fix from $1,950 2011-09-23
Websphere Commerce HIGH 10.0
CVE-2011-3577

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which…

Mitigation only
Fix from $1,950 2011-09-20
Opensaml MEDIUM 5.8
CVE-2011-1411

Shibboleth OpenSAML library 2.4.x before 2.4.3 and 2.5.x before 2.5.1, and IdP before 2.3.2, allows remote attackers to forge messages and bypass aut…

Fix: after 2.3.1
Fix from $1,600 2011-09-02
Lifesize Room Appliance Software MEDIUM 5.0
CVE-2011-2762

The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) allows remote attackers to bypass authentication via unspecified data associated w…

No fix yet
Fix from $1,600 2011-09-02
Rsa Adaptive Authentication On Premise HIGH 7.5
CVE-2011-2733

EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not prevent reuse of authenticatio…

Mitigation only
Fix from $1,950 2011-08-18
Torque Resource Manager HIGH 7.5
CVE-2011-2907

Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 3.0.1 and earlier allows remote attackers to bypass host-based authent…

Fix: after 3.0.1
Fix from $1,950 2011-08-15
Tc Server MEDIUM 5.0
CVE-2011-0527

VMware vFabric tc Server (aka SpringSource tc Server) 2.0.x before 2.0.6.RELEASE and 2.1.x before 2.1.2.RELEASE accepts obfuscated passwords during J…

Mitigation only
Fix from $1,600 2011-08-15
Tivoli Federated Identity Manager MEDIUM 6.8
CVE-2009-5083

IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login re…

No fix yet
Fix from $1,600 2011-08-12
Freeradius MEDIUM 5.8
CVE-2011-2701

The ocsp_check function in rlm_eap_tls.c in FreeRADIUS 2.1.11, when OCSP is enabled, does not properly parse replies from OCSP responders, which allo…

Patch available
Fix from $1,600 2011-08-04
Movicon HIGH 10.0
CVE-2011-2963EPSS 8%

TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to…

Patch available
Fix from $1,950 2011-07-29
Daqfactory HIGH 7.8
CVE-2011-2956EPSS 7%

AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of …

Fix: after 5.84
Fix from $1,950 2011-07-28
Tivoli Directory Server MEDIUM 5.0
CVE-2011-2758

IDSWebApp in the Web Administration Tool in IBM Tivoli Directory Server (TDS) 6.2 before 6.2.0.3-TIV-ITDS-IF0004 does not require authentication for …

Mitigation only
Fix from $1,600 2011-07-17
Servicedesk Plus MEDIUM 5.0
CVE-2011-2756

FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files …

Mitigation only
Fix from $1,600 2011-07-17
Fex MEDIUM 5.0
CVE-2011-1409

Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication an…

Patch available
Fix from $1,600 2011-06-24
Cre Loaded HIGH 7.5
CVE-2009-5077

CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SEL…

Fix: after 6.2
Fix from $1,950 2011-06-08
Cre Loaded HIGH 7.5
CVE-2009-5076

CRE Loaded before 6.2.14, and possibly other versions before 6.3.x, allows remote attackers to bypass authentication and gain administrator privilege…

Fix: after 6.2
Fix from $1,950 2011-06-08
Mediawiki MEDIUM 5.8
CVE-2011-1766

includes/User.php in MediaWiki before 1.16.5, when wgBlockDisablesLogin is enabled, does not clear certain cached data after verification of an auth …

Fix: after 1.16.4
Fix from $1,600 2011-05-23
Smarterstats HIGH 7.5
CVE-2011-2155

Login.aspx in the SmarterTools SmarterStats 6.0 web server generates a ctl00$MPH$txtPassword password form field without disabling the autocomplete f…

Mitigation only
Fix from $1,950 2011-05-20
Messaging Security Gateway HIGH 7.5
CVE-2011-1901

The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3, 5.5.4, …

Fix: after 6.2.0.263
Fix from $1,950 2011-05-05
Prosafe Wnap210 MEDIUM 6.8
CVE-2011-1674

The NetGear ProSafe WNAP210 with firmware 2.0.12 allows remote attackers to bypass authentication and obtain access to the configuration page by visi…

Mitigation only
Fix from $1,600 2011-04-10
Aix MEDIUM 6.8
CVE-2011-1561

The LDAP login feature in bos.rte.security 6.1.6.4 in IBM AIX 6.1, when ldap_auth is enabled in ldap.cfg, allows remote attackers to bypass authentic…

Mitigation only
Fix from $1,600 2011-04-05
E75 Firmware HIGH 7.2
CVE-2011-1472

The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified bu…

Fix: after 211.12
Fix from $1,950 2011-03-29
Lotus Domino HIGH 7.2
CVE-2011-1520

The default configuration of the server console in IBM Lotus Domino does not require a password (aka Server_Console_Password), which allows physicall…

Mitigation only
Fix from $1,950 2011-03-25