Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Virtual Desktop Infrastructure HIGH 7.5
CVE-2009-3923

The VirtualBox 2.0.8 and 2.0.10 web service in Sun Virtual Desktop Infrastructure (VDI) 3.0 does not require authentication, which allows remote atta…

Patch available
Fix from $1,950 2009-11-10
Edirectory MEDIUM 5.0
CVE-2009-3862

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search re…

Patch available
Fix from $1,600 2009-11-04
TYPO3 MEDIUM 6.8
CVE-2009-3635

The Install Tool subcomponent in TYPO3 4.0.13 and earlier, 4.1.x before 4.1.13, 4.2.x before 4.2.10, and 4.3.x before 4.3beta2 allows remote attacker…

Fix: after 4.0.12
Fix from $1,600 2009-11-02
Linux Kernel HIGH 7.8
CVE-2009-3623

The lookup_cb_cred function in fs/nfsd/nfs4callback.c in the nfsd4 subsystem in the Linux kernel before 2.6.31.2 attempts to access a credentials cac…

Fix: after 2.6.31.1
Fix from $1,950 2009-10-30
Edr1600 MEDIUM 5.0
CVE-2009-3828

The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.

No fix yet
Fix from $1,600 2009-10-30
Shared Sign On MEDIUM 5.8
CVE-2009-3657

Session fixation vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack web sessions via unspecified vec…

Patch available
Fix from $1,600 2009-10-09
Com Icrmbasic HIGH 7.5
CVE-2009-3481

A certain interface in the iCRM Basic (com_icrmbasic) component 1.4.2.31 for Joomla! does not require administrative authentication, which has unspec…

Mitigation only
Fix from $1,950 2009-09-30
Ossim MEDIUM 5.0
CVE-2009-3441

Open Source Security Information Management (OSSIM) before 2.1.2 allows remote attackers to bypass authentication, and read graphs or infrastructure …

Fix: after 2.1
Fix from $1,600 2009-09-28
iOS HIGH 7.1
CVE-2009-2863

Race condition in the Firewall Authentication Proxy feature in Cisco IOS 12.0 through 12.4 allows remote attackers to bypass authentication, or bypas…

Mitigation only
Fix from $1,950 2009-09-28
Pao Bacheca Guestbook CRITICAL 9.8
CVE-2009-3421

login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrati…

No fix yet
Fix from $2,300 2009-09-25
Paoliber MEDIUM 6.8
CVE-2009-3422

login.php in Zenas PaoLiber 1.1, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by…

No fix yet
Fix from $1,600 2009-09-25
Paolink MEDIUM 6.8
CVE-2009-3423

login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative access by …

No fix yet
Fix from $1,600 2009-09-25
Livestreet HIGH 7.5
CVE-2009-3261

update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE …

No fix yet
Fix from $1,950 2009-09-18
PostgreSQL MEDIUM 6.8
CVE-2009-3231EPSS 8%

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote at…

Fix: 8.2.14 / 8.3.8+
Fix from $1,600 2009-09-17
Simplephpweb HIGH 7.5
CVE-2009-3158

admin/files.php in simplePHPWeb 0.2 does not require authentication, which allows remote attackers to perform unspecified administrative actions via …

No fix yet
Fix from $1,950 2009-09-10
Otmanager Cms HIGH 7.5
CVE-2008-7179

OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMIN_Hora, ADMIN_Logado, and ADM…

No fix yet
Fix from $1,950 2009-09-08
Gdm MEDIUM 6.8
CVE-2009-2697

The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which m…

Fix: after 2.16
Fix from $1,600 2009-09-04
Ekinboard MEDIUM 6.8
CVE-2008-7156

EkinBoard 1.1.0 and earlier, when register_globals is enabled, allows remote attackers to bypass authorization and gain administrator privileges by s…

Fix: after 1.1.0
Fix from $1,600 2009-09-02
Zkup HIGH 7.5
CVE-2008-7124EPSS 9%

zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain a…

Patch available
Fix from $1,950 2009-08-31
Maian Greetings HIGH 7.5
CVE-2008-7086EPSS 7%

Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the mecard_admin_cookie cookie to …

No fix yet
Fix from $1,950 2009-08-26
Icy Box Nas HIGH 10.0
CVE-2008-7081

userHandler.cgi in RaidSonic ICY BOX NAS firmware 2.3.2.IB.2.RS.1 allows remote attackers to bypass authentication and gain administrator privileges …

Mitigation only
Fix from $1,950 2009-08-25
Free Polling Script MEDIUM 6.4
CVE-2008-7045

AJ Square Free Polling Script (AJPoll) Database version allows remote attackers to bypass authentication and reset poll votes via a direct request to…

No fix yet
Fix from $1,600 2009-08-24
Free Polling Script MEDIUM 6.4
CVE-2008-7046

AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direct request to admin/include/ne…

Mitigation only
Fix from $1,600 2009-08-24
Natterchat HIGH 7.5
CVE-2008-7047

NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete rooms and messages via a direct r…

No fix yet
Fix from $1,950 2009-08-24
Aj Article HIGH 7.5
CVE-2008-7051

AJ Square AJ Article allows remote attackers to bypass authentication and access administrator functionality via a direct request to (1) user.php, (2…

No fix yet
Fix from $1,950 2009-08-24
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2003-1574

TikiWiki 1.6.1 allows remote attackers to bypass authentication by entering a valid username with an arbitrary password, possibly related to the Inte…

Patch available
Fix from $1,950 2009-08-24
Aj Classifieds HIGH 7.5
CVE-2008-7041

AJ Classifieds allows remote attackers to bypass authentication and gain administrator privileges via a direct request to admin/home.php.

No fix yet
Fix from $1,950 2009-08-24
Esqlanelapse HIGH 7.5
CVE-2008-7019

Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.

No fix yet
Fix from $1,950 2009-08-21
Php Filemanager HIGH 7.5
CVE-2008-7027

Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1.

Fix: after 1.18
Fix from $1,950 2009-08-21
Rpg Board HIGH 7.5
CVE-2008-7028

RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep4u cookie to a certain value.

Fix: after 0.0.8
Fix from $1,950 2009-08-21