Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Grid Engine MEDIUM 5.0
CVE-2009-0046

Sun GridEngine 5.3 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to b…

Fix: after 5.3
Fix from $1,600 2009-01-07
Ntp MEDIUM 5.0
CVE-2009-0021

NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows …

Fix: after 4.2.4p4
Fix from $1,600 2009-01-07
Bind MEDIUM 6.8
CVE-2009-0025EPSS 7%

BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attac…

Mitigation only
Fix from $1,600 2009-01-07
Access Analyzer Cgi MEDIUM 5.8
CVE-2008-5809

futomi CGI Cafe Access Analyzer CGI Standard 4.0.1 and earlier and Access Analyzer CGI Professional 4.11.3 and earlier use a predictable session id, …

Fix: after 4.0.1
Fix from $1,600 2009-01-02
V3 Chat Live Support HIGH 7.5
CVE-2008-5783

admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin co…

No fix yet
Fix from $1,950 2008-12-31
Blackjumbodog MEDIUM 5.0
CVE-2008-5721

SapporoWorks BlackJumboDog (BJD) before 4.2.3 allows remote attackers to bypass authentication and obtain sensitive information via unspecified vecto…

Fix: after 4.2.2
Fix from $1,600 2008-12-26
Slimcms HIGH 7.5
CVE-2008-5708

redirect.php in SlimCMS 1.0.0 does not require authentication, which allows remote attackers to create administrative users by using the newusername …

No fix yet
Fix from $1,950 2008-12-24
Ws Ftp MEDIUM 5.0
CVE-2008-5692EPSS 13%

Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via…

Fix: after 6.1
Fix from $1,600 2008-12-19
Tivoli Provisioning Manager HIGH 8.5
CVE-2008-5686

IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP u…

Patch available
Fix from $1,950 2008-12-19
Mac Os X Server HIGH 10.0
CVE-2008-4223EPSS 5%

Podcast Producer in Apple Mac OS X 10.5 before 10.5.6 allows remote attackers to bypass authentication and gain administrative access via unspecified…

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Pro Clan Manager HIGH 7.5
CVE-2008-5575

Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID paramete…

Fix: after 0.4.2
Fix from $1,950 2008-12-15
Scssboard HIGH 7.5
CVE-2008-5576

admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large va…

No fix yet
Fix from $1,950 2008-12-15
Bandsite Cms HIGH 7.5
CVE-2008-5497

BandSite CMS 1.1.4 allows remote attackers to bypass authentication and gain administrative access by setting the login_auth cookie to true.

No fix yet
Fix from $1,950 2008-12-12
Office Sharepoint Server HIGH 7.5
CVE-2008-4032EPSS 48%

Microsoft Office SharePoint Server 2007 Gold and SP1 and Microsoft Search Server 2008 do not properly perform authentication and authorization for ad…

Mitigation only
Fix from $1,950 2008-12-10
Backup Exec For Windows Server HIGH 9.4
CVE-2008-5407

Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds …

Patch available
Fix from $1,950 2008-12-10
Jdk HIGH 10.0
CVE-2008-5355EPSS 8%

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and …

Fix: after 6
Fix from $1,950 2008-12-05
Gallery MEDIUM 6.8
CVE-2008-5296

Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain admin…

Fix: after 1.6
Fix from $1,600 2008-12-01
Videoscript HIGH 7.5
CVE-2008-5219EPSS 7%

The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authentication and does not require …

Fix: after 4.0.1.50
Fix from $1,950 2008-11-25
Wportfolio HIGH 7.5
CVE-2008-5221

The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not require knowledge of the ori…

Fix: after 0.3
Fix from $1,950 2008-11-25
Wincome Mpd Total HIGH 7.5
CVE-2008-5158

Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vector…

Fix: after 3.0.2.623
Fix from $1,950 2008-11-18
Secure Ftp Applet HIGH 7.5
CVE-2008-5124

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attacke…

Fix: after 4.8.0
Fix from $1,950 2008-11-18
Ccleague MEDIUM 6.8
CVE-2008-5125

admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

No fix yet
Fix from $1,600 2008-11-18
Serverprotect HIGH 10.0
CVE-2006-5268EPSS 7%

Unspecified vulnerability in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via vectors related to obtainin…

Mitigation only
Fix from $1,950 2008-11-17
Tlguesbook HIGH 7.5
CVE-2008-5065

TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBook_login cookie to admin.

No fix yet
Fix from $1,950 2008-11-13
Firefox HIGH 7.5
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaM…

Fix: 1.1.13 / 2.0.0.18+
Fix from $1,950 2008-11-13
Windows HIGH 9.3
CVE-2008-4037EPSS 59%

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers …

Patch available
Fix from $1,950 2008-11-12
Photovideotube HIGH 7.5
CVE-2008-5042

Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks via a direct request to admi…

Fix: after 1.1
Fix from $1,950 2008-11-12
Myforum HIGH 7.5
CVE-2008-5040

Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum…

No fix yet
Fix from $1,950 2008-11-12
Tlads HIGH 7.5
CVE-2008-4783

tlAds 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tlAds_login cookie to "admin."

No fix yet
Fix from $1,950 2008-10-29
Aflog HIGH 7.5
CVE-2008-4784

aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a cookie to "A" or "O" in (1) ed…

No fix yet
Fix from $1,950 2008-10-29