Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Tlnews HIGH 7.5
CVE-2008-4752

TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin.

No fix yet
Fix from $1,950 2008-10-27
Integrated Lights Out Manager HIGH 9.0
CVE-2008-4722

Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the se…

Fix: after 7.1.6
Fix from $1,950 2008-10-23
Post Comment HIGH 7.5
CVE-2008-4721

PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie …

No fix yet
Fix from $1,950 2008-10-23
Bbzl.php HIGH 7.5
CVE-2008-4708

BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1.

No fix yet
Fix from $1,950 2008-10-23
Atomic Photo Album HIGH 7.5
CVE-2008-4714

Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers t…

No fix yet
Fix from $1,950 2008-10-23
Mantis HIGH 7.5
CVE-2008-4689

Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

Fix: after 1.1.2
Fix from $1,950 2008-10-22
Websphere Application Server MEDIUM 6.8
CVE-2008-4679

The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store C…

Patch available
Fix from $1,600 2008-10-22
Elxis Cms HIGH 7.5
CVE-2008-4649

Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

No fix yet
Fix from $1,950 2008-10-22
Phpfastnews HIGH 7.5
CVE-2008-4622

The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by …

No fix yet
Fix from $1,950 2008-10-21
Portalapp HIGH 7.5
CVE-2008-4614

PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topi…

Patch available
Fix from $1,950 2008-10-20
Linux Kernel HIGH 7.8
CVE-2008-4576

sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not suppo…

Fix: after 2.6.25.17
Fix from $1,950 2008-10-15
Host Integration Server 2000 HIGH 10.0
CVE-2008-3466EPSS 78%

Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to …

Patch available
Fix from $1,950 2008-10-15
K9 Web Protection HIGH 7.5
CVE-2008-4515

Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authenti…

Mitigation only
Fix from $1,950 2008-10-09
Unity MEDIUM 5.8
CVE-2008-3814

Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication…

Patch available
Fix from $1,600 2008-10-08
Personal Information Manager HIGH 7.5
CVE-2008-4427

changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows re…

Fix: after 1.0
Fix from $1,950 2008-10-03
Php Filemanager MEDIUM 6.4
CVE-2008-4319

fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrar…

Fix: after 1.18
Fix from $1,600 2008-09-29
Rianxosencabos Cms HIGH 7.5
CVE-2008-4244

Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.

No fix yet
Fix from $1,950 2008-09-25
Addalink MEDIUM 5.0
CVE-2008-4146

Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-coun…

Fix: after 1.0
Fix from $1,600 2008-09-24
Ezphotogallery MEDIUM 6.4
CVE-2008-4167

useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add…

No fix yet
Fix from $1,600 2008-09-22
Mac Os X HIGH 7.6
CVE-2008-3610

Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password a…

Patch available
Fix from $1,950 2008-09-16
Mac Os X MEDIUM 6.3
CVE-2008-3611

Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, whic…

Patch available
Fix from $1,600 2008-09-16
Stash HIGH 7.5
CVE-2008-4081

admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.

No fix yet
Fix from $1,950 2008-09-15
Ruby MEDIUM 5.8
CVE-2008-3905

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and …

Fix: after 1.9
Fix from $1,600 2008-09-04
Google Apps HIGH 7.5
CVE-2008-3891

The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors…

Mitigation only
Fix from $1,950 2008-09-03
Lacoodast CRITICAL 9.1
CVE-2008-3738

Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 2.1.3
Fix from $2,300 2008-08-27
Mailscan HIGH 7.5
CVE-2008-3729

Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrati…

No fix yet
Fix from $1,950 2008-08-20
Veritas Storage Foundation HIGH 10.0
CVE-2008-3703EPSS 12%

The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0,…

Patch available
Fix from $1,950 2008-08-18
Atmail HIGH 7.8
CVE-2008-3579

Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,950 2008-08-10
Plain Black Webgui MEDIUM 5.0
CVE-2008-3503

RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers…

Mitigation only
Fix from $1,600 2008-08-06
Mask Php File Manager HIGH 7.5
CVE-2008-3504

Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies…

Fix: after 2.2
Fix from $1,950 2008-08-06