Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Db2 Universal Database MEDIUM 6.4
CVE-2010-3739

The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and…

Fix: after 9.5
Fix from $1,600 2010-10-05
Drupal MEDIUM 5.0
CVE-2010-3685

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking fo…

Patch available
Fix from $1,600 2010-09-29
Drupal MEDIUM 5.0
CVE-2010-3686

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring th…

Patch available
Fix from $1,600 2010-09-29
Drupal MEDIUM 5.0
CVE-2010-3091

The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying t…

Patch available
Fix from $1,600 2010-09-29
Mac Os X MEDIUM 6.8
CVE-2010-1820

Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass t…

Patch available
Fix from $1,600 2010-09-21
Unclassified MEDIUM 6.8
CVE-2010-2731EPSS 31%

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enable…

Mitigation only
Fix from $1,600 2010-09-15
Sssd MEDIUM 5.1
CVE-2010-2940

The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are…

Mitigation only
Fix from $1,600 2010-08-30
Libsecurity MEDIUM 6.4
CVE-2010-1802

libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-…

Patch available
Fix from $1,600 2010-08-25
Free Image Hosting Script HIGH 7.5
CVE-2009-4987EPSS 6%

admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by settin…

No fix yet
Fix from $1,950 2010-08-25
Zope Ldapuserfolder HIGH 7.5
CVE-2010-2944

The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, wh…

Patch available
Fix from $1,950 2010-08-20
Ubuntu Linux HIGH 9.3
CVE-2010-0834

The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 ne…

Patch available
Fix from $1,950 2010-08-10
Tivoli Directory Server MEDIUM 5.0
CVE-2010-2927

The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of ser…

Fix: after 6.0.0.8
Fix from $1,600 2010-08-02
Likewise Open HIGH 9.3
CVE-2010-0833

The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storag…

Patch available
Fix from $1,950 2010-07-28
Wbnews HIGH 7.5
CVE-2009-4927

WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by settin…

No fix yet
Fix from $1,950 2010-07-12
Totalcalender HIGH 7.5
CVE-2009-4929

admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwor…

No fix yet
Fix from $1,950 2010-07-12
Alpha Ethernet Adapter Ii Web Manager MEDIUM 6.4
CVE-2010-2668

Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and…

Mitigation only
Fix from $1,600 2010-07-08
Mahara HIGH 7.5
CVE-2010-1670

Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins…

Fix: after 1.0.14
Fix from $1,950 2010-07-06
Open Ftpd HIGH 9.3
CVE-2010-2620EPSS 30%

Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or othe…

Fix: after 1.2
Fix from $1,950 2010-07-02
Oblog MEDIUM 6.8
CVE-2009-4909

admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests.

No fix yet
Fix from $1,600 2010-06-25
Workspace Streaming HIGH 9.3
CVE-2008-4389

Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Work…

Mitigation only
Fix from $1,950 2010-06-17
Mac Os X HIGH 7.2
CVE-2010-1375

NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to …

Patch available
Fix from $1,950 2010-06-17
Scientific Atlanta Webstar Dpc2100r2 MEDIUM 6.4
CVE-2010-2026

The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass aut…

No fix yet
Fix from $1,600 2010-05-26
Tc Server MEDIUM 6.8
CVE-2010-1454

com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25…

Mitigation only
Fix from $1,600 2010-05-19
Consona Dynamic Agent MEDIUM 5.1
CVE-2010-1910

The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of…

Patch available
Fix from $1,600 2010-05-12
Virtualiq HIGH 7.5
CVE-2009-4843

ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attacker…

No fix yet
Fix from $1,950 2010-05-07
Moodle MEDIUM 6.8
CVE-2010-1613

Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2010-04-29
Support Incident Tracker MEDIUM 6.8
CVE-2010-1596

Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an em…

Fix: after 3.50
Fix from $1,600 2010-04-28
Openx HIGH 7.5
CVE-2009-4830

Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via…

Patch available
Fix from $1,950 2010-04-27
Dir 615 MEDIUM 5.0
CVE-2009-4821

The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the…

No fix yet
Fix from $1,600 2010-04-27
Php Article Publisher HIGH 7.5
CVE-2009-4808

admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_adm…

No fix yet
Fix from $1,950 2010-04-23