Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Lotus Domino HIGH 10.0
CVE-2011-1519EPSS 9%

The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname speci…

Mitigation only
Fix from $1,950 2011-03-25
Openldap MEDIUM 6.8
CVE-2011-1025

bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attack…

Patch available
Fix from $1,600 2011-03-20
Nss Pam Ldapd MEDIUM 6.8
CVE-2011-0438

nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass au…

Patch available
Fix from $1,600 2011-03-15
Domain Technologie Control MEDIUM 5.0
CVE-2011-0435

Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which …

Fix: after 0.32.8
Fix from $1,600 2011-03-07
Network Satellite Server MEDIUM 5.8
CVE-2011-0718

Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond…

Mitigation only
Fix from $1,600 2011-02-25
Telepresence Recording Server Software HIGH 7.5
CVE-2011-0392

Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Manager HIGH 7.5
CVE-2011-0380

Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP req…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Recording Server Software HIGH 10.0
CVE-2011-0383EPSS 6%

The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Multipoint Switch Software HIGH 10.0
CVE-2011-0384EPSS 6%

The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require admin…

Mitigation only
Fix from $1,950 2011-02-25
Internet Gatekeeper MEDIUM 5.0
CVE-2011-0453

F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obta…

Patch available
Fix from $1,600 2011-02-18
Windows 2003 Server HIGH 7.2
CVE-2011-0039

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authenticati…

Mitigation only
Fix from $1,950 2011-02-09
Lotus Domino HIGH 9.3
CVE-2011-0920EPSS 10%

The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to by…

Mitigation only
Fix from $1,950 2011-02-08
Antivirus HIGH 9.3
CVE-2011-0688

Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente…

Mitigation only
Fix from $1,950 2011-01-31
Objectivity\/db HIGH 7.5
CVE-2011-0489EPSS 13%

The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data,…

No fix yet
Fix from $1,950 2011-01-18
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2010-4690

The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly …

Fix: after 8.3
Fix from $1,600 2011-01-07
Esxi HIGH 9.3
CVE-2010-4573

The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows …

Mitigation only
Fix from $1,950 2010-12-22
Eucalyptus HIGH 7.5
CVE-2010-3905

The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attacke…

Mitigation only
Fix from $1,950 2010-12-22
Pointter Php Content Management System HIGH 7.5
CVE-2010-4332EPSS 7%

Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values…

No fix yet
Fix from $1,950 2010-12-22
Pointter Php Micro Blogging Social Network HIGH 7.5
CVE-2010-4333EPSS 7%

Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary va…

No fix yet
Fix from $1,950 2010-12-22
phpMyAdmin MEDIUM 5.0
CVE-2010-4481

phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, …

Fix: after 3.3.9.0
Fix from $1,600 2010-12-17
Chrome MEDIUM 5.0
CVE-2010-4488

Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (appl…

Fix: after 8.0.552.214
Fix from $1,600 2010-12-07
Openssh CRITICAL 9.8
CVE-2010-4478

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attacke…

Fix: after 5.6
Fix from $2,300 2010-12-06
Pandora Fms HIGH 10.0
CVE-2010-4279EPSS 66%

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypa…

Fix: after 3.1
Fix from $1,950 2010-12-02
Certificate System MEDIUM 5.8
CVE-2010-3868

Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w…

Patch available
Fix from $1,600 2010-11-17
Cmnc 200 Firmware HIGH 10.0
CVE-2010-4232

The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 all…

No fix yet
Fix from $1,950 2010-11-17
Omnifind HIGH 7.5
CVE-2010-3896

The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers …

No fix yet
Fix from $1,950 2010-11-12
Luci MEDIUM 6.4
CVE-2010-3852

The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easie…

Fix: after 0.22.4
Fix from $1,600 2010-11-06
Tivoli Provisioning Manager Os Deployment HIGH 7.5
CVE-2010-4121

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows…

Mitigation only
Fix from $1,950 2010-10-28
Pyftpdlib HIGH 7.5
CVE-2008-7263

ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attacke…

Fix: after 0.4.0
Fix from $1,950 2010-10-19
Pyftpdlib HIGH 7.5
CVE-2007-6737

FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which mak…

Fix: after 0.1.1
Fix from $1,950 2010-10-19