Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ez Blog HIGH 7.5
CVE-2009-4801

EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.

No fix yet
Fix from $1,950 2010-04-23
Digital Interchange Document Library HIGH 7.5
CVE-2009-4806

admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to re…

No fix yet
Fix from $1,950 2010-04-23
Alvaros Messenger MEDIUM 5.8
CVE-2010-0744

aMSN (aka Alvaro's Messenger) 0.98.3 and earlier, when SSL is used, does not verify that the server hostname matches a domain name in the subject's C…

Fix: after 0.98.3
Fix from $1,600 2010-04-20
Xosoft Content Distribution MEDIUM 5.0
CVE-2010-1221

CA XOsoft r12.0 and r12.5 does not properly perform authentication, which allows remote attackers to enumerate usernames via a SOAP request.

Patch available
Fix from $1,600 2010-04-07
Xosoft Content Distribution MEDIUM 5.0
CVE-2010-1222

CA XOsoft r12.5 does not properly perform authentication, which allows remote attackers to obtain potentially sensitive information via a SOAP reques…

Patch available
Fix from $1,600 2010-04-07
Varnish HIGH 7.5
CVE-2009-2936EPSS 64%

The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 doe…

Mitigation only
Fix from $1,950 2010-04-05
Sahana MEDIUM 6.4
CVE-2010-1191

Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable ad…

Mitigation only
Fix from $1,600 2010-03-31
Mac Os X MEDIUM 5.0
CVE-2010-0521

Server Admin in Apple Mac OS X Server before 10.6.3 does not properly enforce authentication for directory binding, which allows remote attackers to …

Fix: after 10.6.2
Fix from $1,600 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0498

Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local user…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Dedecms MEDIUM 6.8
CVE-2010-1097

include/userlogin.class.php in DeDeCMS 5.5 GBK, when session.auto_start is enabled, allows remote attackers to bypass authentication and gain adminis…

No fix yet
Fix from $1,600 2010-03-24
Openpne MEDIUM 5.8
CVE-2010-1040

The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device su…

Mitigation only
Fix from $1,600 2010-03-23
T3sec Saltedpw HIGH 7.5
CVE-2010-1022

The TYPO3 Security - Salted user password hashes (t3sec_saltedpw) extension before 0.2.13 for TYPO3 allows remote attackers to bypass authentication …

Fix: after 0.2.12
Fix from $1,950 2010-03-19
Openview Performance Insight HIGH 10.0
CVE-2010-0447EPSS 5%

The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate reque…

Fix: after 5.4
Fix from $1,950 2010-03-10
Roomphplanning HIGH 7.5
CVE-2009-4670

admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arbitrary users via the user par…

No fix yet
Fix from $1,950 2010-03-05
Roomphplanning HIGH 7.5
CVE-2009-4671

Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by setting the room_phplanning cook…

No fix yet
Fix from $1,950 2010-03-05
Gastro Portal \(restaurant Directory\) Script HIGH 7.5
CVE-2009-4675

admin/admin_info/index.php in the Mole Group Gastro Portal (Restaurant Directory) Script does not require administrative authentication, which allows…

No fix yet
Fix from $1,950 2010-03-05
Xerver HIGH 7.5
CVE-2009-4657

The administrator package for Xerver 4.32 does not require authentication, which allows remote attackers to alter application settings by connecting …

No fix yet
Fix from $1,950 2010-03-03
Wikyblog MEDIUM 5.8
CVE-2010-0756

Session fixation vulnerability in WikyBlog 1.7.3 rc2 allows remote attackers to hijack web sessions by setting the jsessionid parameter to (1) index.…

No fix yet
Fix from $1,600 2010-02-27
Geo\+\+ Gncaster HIGH 7.5
CVE-2010-0554

The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attacker…

Fix: after 1.4.0.7
Fix from $1,950 2010-02-04
Db Masters Multimedia Links Directory HIGH 7.5
CVE-2009-4584

admin.php in dB Masters Multimedia Links Directory 3.1.3 allows remote attackers to bypass authentication and gain administrative access via a certai…

No fix yet
Fix from $1,950 2010-01-06
Jax Guestbook HIGH 7.5
CVE-2009-4447

Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct request to admin/guestbook.admin.…

No fix yet
Fix from $1,950 2009-12-29
Staging Module MEDIUM 6.8
CVE-2009-4367EPSS 6%

The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and earlier allows remote attackers …

Fix: after 5.4.0
Fix from $1,600 2009-12-21
Backup Exec Continuous Protection Server HIGH 10.0
CVE-2009-3027EPSS 11%

VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0…

Patch available
Fix from $1,950 2009-12-11
Com Kide MEDIUM 5.0
CVE-2009-4232

The Kide Shoutbox (com_kide) component 0.4.6 for Joomla! does not properly perform authentication, which allows remote attackers to post messages wit…

Mitigation only
Fix from $1,600 2009-12-08
Rt MEDIUM 5.8
CVE-2009-3585

Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows …

Patch available
Fix from $1,600 2009-12-02
Rt MEDIUM 5.8
CVE-2009-4151

Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.5 allows …

Patch available
Fix from $1,600 2009-12-02
Grub 2 HIGH 7.2
CVE-2009-4128

GNU GRand Unified Bootloader (GRUB) 2 1.97 only compares the submitted portion of a password with the actual password, which makes it easier for phys…

Patch available
Fix from $1,950 2009-12-01
Myphile HIGH 7.5
CVE-2009-4095

myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party info…

Patch available
Fix from $1,950 2009-11-29
Telepark.wiki MEDIUM 5.0
CVE-2009-4089EPSS 7%

telepark.wiki 2.4.23 and earlier allows remote attackers to bypass authorization and (1) delete arbitrary pages via a modified pageID parameter to aj…

No fix yet
Fix from $1,600 2009-11-29
Arcade Trade Script HIGH 7.5
CVE-2009-3966

Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the adminLoggedIn cookie to true.

No fix yet
Fix from $1,950 2009-11-18