Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mac Os X HIGH 10.0
CVE-2009-0138

servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify t…

Patch available
Fix from $1,950 2009-02-13
Goople Cms HIGH 7.5
CVE-2008-6118

win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cook…

No fix yet
Fix from $1,950 2009-02-11
Ware Support HIGH 7.5
CVE-2009-0460

Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cook…

No fix yet
Fix from $1,950 2009-02-10
Password Protect HIGH 7.5
CVE-2009-0461

Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in th…

No fix yet
Fix from $1,950 2009-02-10
Simpleircbot HIGH 10.0
CVE-2009-0492

Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability."

Patch available
Fix from $1,950 2009-02-10
Ranking Script HIGH 7.5
CVE-2008-6092

phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie.

No fix yet
Fix from $1,950 2009-02-09
Goahead Webserver MEDIUM 5.0
CVE-2002-2427

The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content vi…

Fix: after 2.1
Fix from $1,600 2009-02-06
Shopping Cart HIGH 7.5
CVE-2009-0412

The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication…

Mitigation only
Fix from $1,950 2009-02-03
Bluepage Cms MEDIUM 6.8
CVE-2008-6039

Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

Fix: 2.5.8+
Fix from $1,600 2009-02-03
Xt Commerce MEDIUM 6.8
CVE-2008-6045

Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XT…

Fix: after 3.0.4
Fix from $1,600 2009-02-03
Dogtag Certificate System MEDIUM 6.0
CVE-2008-5082

The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S…

Mitigation only
Fix from $1,600 2009-01-30
Sg Real Estate Portal HIGH 7.5
CVE-2008-6009

SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.

No fix yet
Fix from $1,950 2009-01-30
Asp Project HIGH 7.5
CVE-2009-0280

Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1.

No fix yet
Fix from $1,950 2009-01-27
Phpicalendar HIGH 7.5
CVE-2008-5967

admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote…

Fix: after 2.3.4
Fix from $1,950 2009-01-26
Impresscms MEDIUM 6.8
CVE-2008-5964

Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID paramete…

Fix: after 1.0.3
Fix from $1,600 2009-01-23
TYPO3 HIGH 7.5
CVE-2009-0256

Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote…

Mitigation only
Fix from $1,950 2009-01-22
Nukeviet HIGH 7.5
CVE-2008-5945

Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provena…

No fix yet
Fix from $1,950 2009-01-22
Squirrelmail MEDIUM 6.5
CVE-2009-0030

A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce…

Mitigation only
Fix from $1,600 2009-01-21
Tqsllib MEDIUM 5.0
CVE-2009-0124

The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from…

No fix yet
Fix from $1,600 2009-01-15
Libnasl MEDIUM 5.0
CVE-2009-0125

NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 d…

No fix yet
Fix from $1,600 2009-01-15
Boinc Client MEDIUM 5.0
CVE-2009-0126

The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not ch…

No fix yet
Fix from $1,600 2009-01-15
M2crypto MEDIUM 5.0
CVE-2009-0127

M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify func…

No fix yet
Fix from $1,600 2009-01-15
Slurm MEDIUM 5.0
CVE-2009-0128

plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return …

No fix yet
Fix from $1,600 2009-01-15
Libcrypt Openssl Dsa Perl MEDIUM 5.0
CVE-2009-0129

libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote …

No fix yet
Fix from $1,600 2009-01-15
Erlang HIGH 7.5
CVE-2009-0130

lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote at…

No fix yet
Fix from $1,950 2009-01-15
Gobbl Cms HIGH 7.5
CVE-2008-5880

admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok".

No fix yet
Fix from $1,950 2009-01-08
Openevidence MEDIUM 5.0
CVE-2009-0048

OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to b…

Fix: after 1.0.6
Fix from $1,600 2009-01-07
Eidlib MEDIUM 5.0
CVE-2009-0049

Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows re…

Fix: after 2.6.0
Fix from $1,600 2009-01-07
Zxid MEDIUM 5.0
CVE-2009-0051

ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validati…

Fix: after 0.29
Fix from $1,600 2009-01-07
Gale MEDIUM 5.0
CVE-2009-0047

Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass val…

Fix: after 0.99
Fix from $1,600 2009-01-07