Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mypicgallery HIGH 7.5
CVE-2008-2347

MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admi…

No fix yet
Fix from $1,950 2008-05-20
Internet Photoshow HIGH 7.5
CVE-2008-2282

admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_adm…

No fix yet
Fix from $1,950 2008-05-18
Web Slider HIGH 7.5
CVE-2008-2298

Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.

No fix yet
Fix from $1,950 2008-05-18
Austinsmoke Gastracker HIGH 7.5
CVE-2008-2269

AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin coo…

No fix yet
Fix from $1,950 2008-05-16
WordPress HIGH 7.5
CVE-2008-1930EPSS 5%

The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote …

Patch available
Fix from $1,950 2008-04-28
Phshoutbox Final HIGH 7.5
CVE-2008-1971

phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) …

Fix: after 1.5
Fix from $1,950 2008-04-27
Mylo Com 2 MEDIUM 6.4
CVE-2008-1938

Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain se…

Fix: after 1.100
Fix from $1,600 2008-04-25
Ccmail HIGH 7.5
CVE-2008-1904

Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attacke…

Fix: after 1.0.1
Fix from $1,950 2008-04-22
Blackboard Academic Suite MEDIUM 6.8
CVE-2008-1883

The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attack…

Fix: after 7
Fix from $1,600 2008-04-18
Dbmail MEDIUM 6.8
CVE-2007-6714

DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypas…

Patch available
Fix from $1,600 2008-04-17
Pixel Motion Blog HIGH 7.5
CVE-2008-1868

admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b…

No fix yet
Fix from $1,950 2008-04-17
Knowledgequest HIGH 7.5
CVE-2008-1727EPSS 7%

KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin acco…

No fix yet
Fix from $1,950 2008-04-11
Emergency Responder HIGH 10.0
CVE-2008-1154EPSS 5%

The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and…

Patch available
Fix from $1,950 2008-04-04
Apache Ssl HIGH 7.5
CVE-2008-0555

The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (…

Patch available
Fix from $1,950 2008-04-04
Presario A900 HIGH 7.2
CVE-2008-0706

Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged acces…

Patch available
Fix from $1,950 2008-03-31
Edirectory HIGH 7.5
CVE-2008-0926EPSS 58%

The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which …

Fix: after 8.7.3.10
Fix from $1,950 2008-03-28
Firefox MEDIUM 5.0
CVE-2008-1238

Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba…

Fix: after 2.0.0.12
Fix from $1,600 2008-03-27
Gallarific MEDIUM 6.4
CVE-2008-1469

Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote…

Mitigation only
Fix from $1,600 2008-03-24
Plone Cms HIGH 7.5
CVE-2008-1395

Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex…

Mitigation only
Fix from $1,950 2008-03-20
Solaris MEDIUM 6.3
CVE-2008-1356

Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local us…

Patch available
Fix from $1,600 2008-03-17
Home Hub HIGH 7.5
CVE-2008-1334

cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP t…

No fix yet
Fix from $1,950 2008-03-13
Asg Sentry MEDIUM 5.0
CVE-2008-1321EPSS 8%

The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of …

Fix: after 7.0.0
Fix from $1,600 2008-03-13
Gallarific HIGH 7.5
CVE-2008-1327

Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct requ…

No fix yet
Fix from $1,950 2008-03-13
F5d7230 4 HIGH 10.0
CVE-2008-1244

cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform …

No fix yet
Fix from $1,950 2008-03-10
P 2602hw D1a HIGH 9.3
CVE-2008-1259

The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authent…

No fix yet
Fix from $1,950 2008-03-10
Wimax Prost HIGH 10.0
CVE-2008-1262EPSS 9%

The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remot…

No fix yet
Fix from $1,950 2008-03-10
Wrt54g HIGH 7.5
CVE-2008-1264

The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil…

Mitigation only
Fix from $1,950 2008-03-10
Wrt54g HIGH 10.0
CVE-2008-1268

The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab…

Mitigation only
Fix from $1,950 2008-03-10
Gate2 Plus Wi Fi HIGH 7.1
CVE-2008-1269

cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attac…

No fix yet
Fix from $1,950 2008-03-10
Interneserviceslosungen MEDIUM 6.4
CVE-2008-1134

OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attacke…

Mitigation only
Fix from $1,600 2008-03-04