Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Java System Web Server Plugin MEDIUM 6.5
CVE-2008-3425

Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenti…

Mitigation only
Fix from $1,600 2008-07-31
Phpfreechat MEDIUM 6.5
CVE-2008-3428

Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to mat…

Patch available
Fix from $1,600 2008-07-31
Akw D800 HIGH 10.0
CVE-2008-3411

The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/conf…

Mitigation only
Fix from $1,950 2008-07-31
Phplinkat MEDIUM 5.0
CVE-2008-3407

phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.

No fix yet
Fix from $1,600 2008-07-31
Jamroom HIGH 7.5
CVE-2008-3375

The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrati…

Fix: after 3.3.8
Fix from $1,950 2008-07-30
Maian Search HIGH 7.5
CVE-2008-3317EPSS 8%

admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…

Fix: after 1.1
Fix from $1,950 2008-07-25
Weblog HIGH 7.5
CVE-2008-3318EPSS 8%

admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…

Fix: after 4.0
Fix from $1,950 2008-07-25
Links HIGH 7.5
CVE-2008-3319EPSS 8%

admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar…

Fix: after 3.1
Fix from $1,950 2008-07-25
Guestbook HIGH 7.5
CVE-2008-3320EPSS 7%

admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbi…

Fix: after 3.2
Fix from $1,950 2008-07-25
Maian Uploader HIGH 7.5
CVE-2008-3321EPSS 8%

admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbit…

Fix: after 4.0
Fix from $1,950 2008-07-25
Recipe HIGH 7.5
CVE-2008-3322EPSS 7%

admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…

Fix: after 1.2
Fix from $1,950 2008-07-25
Esyndicat HIGH 7.5
CVE-2008-3299EPSS 6%

eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the p…

No fix yet
Fix from $1,950 2008-07-25
Ezwebalbum MEDIUM 6.4
CVE-2008-3292EPSS 7%

constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin coo…

No fix yet
Fix from $1,600 2008-07-24
Asterisk Appliance Developer Kit HIGH 7.8
CVE-2008-3264

The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B…

Mitigation only
Fix from $1,950 2008-07-24
Free Image Hosting Script HIGH 7.5
CVE-2008-3211

Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cook…

No fix yet
Fix from $1,950 2008-07-18
Auracms HIGH 7.5
CVE-2008-3203

js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web cont…

No fix yet
Fix from $1,950 2008-07-17
Firefox HIGH 7.5
CVE-2008-2801

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Rss Aggregator HIGH 9.3
CVE-2008-3033

RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin f…

Mitigation only
Fix from $1,950 2008-07-07
Eztechhelp Ezcms HIGH 7.5
CVE-2008-2920

admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to creat…

Fix: after 1.2
Fix from $1,950 2008-06-30
Unified Communications Manager MEDIUM 5.0
CVE-2008-2730

The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) …

Patch available
Fix from $1,600 2008-06-26
Benja Cms MEDIUM 6.4
CVE-2008-2879

Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.

No fix yet
Fix from $1,600 2008-06-26
Le.cms HIGH 10.0
CVE-2008-2833

admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in…

Fix: after 1.4
Fix from $1,950 2008-06-24
Java System Access Manager HIGH 9.3
CVE-2008-2705

Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Ente…

No fix yet
Fix from $1,950 2008-06-16
Session And Resource Control HIGH 10.0
CVE-2008-0960EPSS 69%

SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Se…

Patch available
Fix from $1,950 2008-06-10
Client HIGH 7.1
CVE-2008-1106

The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request…

Fix: after 3322
Fix from $1,950 2008-06-09
Java Asp Server HIGH 7.5
CVE-2008-2406

The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via …

Fix: after 4.0.2
Fix from $1,950 2008-06-04
Blogphp MEDIUM 5.0
CVE-2008-2524

BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_user…

Mitigation only
Fix from $1,600 2008-06-03
Access Gateway HIGH 10.0
CVE-2008-2528

Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to by…

Fix: after 4.5.7
Fix from $1,950 2008-06-03
Service Control Engine HIGH 7.8
CVE-2008-0536

Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Ic…

Fix: after 3.1.6
Fix from $1,950 2008-05-22
Gnutls HIGH 9.3
CVE-2008-1949EPSS 6%

The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello m…

Patch available
Fix from $1,950 2008-05-21