Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Ruby On Rails CRITICAL 9.8
CVE-2009-2422

The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_reques…

Fix: 2.3.3 / 10.6.3+
Fix from $2,300 2009-07-10
Phpmyblockchecker CRITICAL 9.8
CVE-2009-2382EPSS 6%

admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin c…

No fix yet
Fix from $2,300 2009-07-08
Kervinet Forum HIGH 7.5
CVE-2009-2328

admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitra…

Fix: after 1.1
Fix from $1,950 2009-07-05
Dg632 HIGH 7.8
CVE-2009-2257EPSS 7%

The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to…

No fix yet
Fix from $1,950 2009-06-30
Zen Cart MEDIUM 6.8
CVE-2009-2255EPSS 31%

Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exe…

Fix: after 1.3.8a
Fix from $1,600 2009-06-30
Gallery Search Engine HIGH 7.5
CVE-2009-2233

The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by set…

No fix yet
Fix from $1,950 2009-06-26
Midas HIGH 7.5
CVE-2009-2231

MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie.

No fix yet
Fix from $1,950 2009-06-26
7ammel CRITICAL 9.8
CVE-2009-2168EPSS 12%

cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials ar…

Fix: after 1.0.1
Fix from $2,300 2009-06-22
Torrenttrader Classic MEDIUM 6.4
CVE-2009-2159

backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and downloa…

No fix yet
Fix from $1,600 2009-06-22
Phportal HIGH 7.5
CVE-2009-2117

uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a v…

No fix yet
Fix from $1,950 2009-06-18
Mutt MEDIUM 6.8
CVE-2009-1390

Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the …

Patch available
Fix from $1,600 2009-06-16
Safari MEDIUM 6.8
CVE-2009-2058

Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p…

Fix: after 3.2.2
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2059

Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from …

Fix: after 9.22
Fix from $1,600 2009-06-15
Chrome MEDIUM 5.8
CVE-2009-2060

src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided…

Fix: after 1.0.154.52
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2062

Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execut…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2063

Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to exe…

Fix: after 9.24
Fix from $1,600 2009-06-15
Internet Explorer MEDIUM 6.8
CVE-2009-2064

Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which a…

Fix: after 8
Fix from $1,600 2009-06-15
Firefox MEDIUM 6.8
CVE-2009-2065

Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m…

Fix: after 3.0.9
Fix from $1,600 2009-06-15
Safari MEDIUM 6.8
CVE-2009-2066

Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute ar…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2067

Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary…

Fix: after 9.22
Fix from $1,600 2009-06-15
Opera MEDIUM 5.8
CVE-2009-2068

Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute a…

Mitigation only
Fix from $1,600 2009-06-15
Ie MEDIUM 5.8
CVE-2009-2069

Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which a…

Mitigation only
Fix from $1,600 2009-06-15
Opera Browser MEDIUM 6.8
CVE-2009-2070

Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attacke…

Mitigation only
Fix from $1,600 2009-06-15
Chrome MEDIUM 6.8
CVE-2009-2071

Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows…

Fix: after 1.0.154.52
Fix from $1,600 2009-06-15
Safari MEDIUM 5.4
CVE-2009-2072

Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to s…

Fix: after 3.2.1
Fix from $1,600 2009-06-15
Ie MEDIUM 5.8
CVE-2009-2057

Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT respon…

No fix yet
Fix from $1,600 2009-06-15
Firefox MEDIUM 6.8
CVE-2009-1836

Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Grestul HIGH 7.5
CVE-2009-2040

admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative …

No fix yet
Fix from $1,950 2009-06-12
Internet Information Services HIGH 7.5
CVE-2009-1122EPSS 98%

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote atta…

Patch available
Fix from $1,950 2009-06-10
Internet Information Services HIGH 7.5
CVE-2009-1535EPSS 98%

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, …

Patch available
Fix from $1,950 2009-06-10