Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Websphere Mq MEDIUM 6.6
CVE-2008-1130

Unspecified vulnerability in IBM WebSphere MQ 6.0.x before 6.0.2.2 and 5.3 before Fix Pack 14 allows attackers to bypass access restrictions for a qu…

Mitigation only
Fix from $1,600 2008-03-04
Weblogic Server MEDIUM 6.4
CVE-2008-0895

BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted reque…

Patch available
Fix from $1,600 2008-02-22
Header Image HIGH 10.0
CVE-2008-0823

Unspecified vulnerability in the Header Image Module before 5.x-1.1 for Drupal allows remote attackers to access the administration pages via unknown…

Patch available
Fix from $1,950 2008-02-19
Ghost Solutions Suite HIGH 10.0
CVE-2008-0640

Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management…

Patch available
Fix from $1,950 2008-02-08
Applications Manager MEDIUM 6.4
CVE-2008-0476

ManageEngine Applications Manager 8.1 build 8100 does not check authentication for monitorType.do and unspecified other pages, which allows remote at…

Mitigation only
Fix from $1,600 2008-01-29
Http File Server MEDIUM 5.0
CVE-2008-0407

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authe…

Fix: after 2.2b
Fix from $1,600 2008-01-29
Http File Server MEDIUM 6.4
CVE-2008-0408

HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text d…

Fix: after 2.2b
Fix from $1,600 2008-01-29
Http File Server MEDIUM 5.0
CVE-2008-0410

HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id…

Fix: after 2.2b
Fix from $1,600 2008-01-29
Web Wiz Forums MEDIUM 5.0
CVE-2008-0466

Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authenticat…

No fix yet
Fix from $1,600 2008-01-29
F5d9230 4 MEDIUM 5.5
CVE-2008-0403

The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, which allows remote attackers to …

No fix yet
Fix from $1,600 2008-01-23
Alitalk HIGH 7.5
CVE-2008-0391

inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arbitrary user account via a mod…

No fix yet
Fix from $1,950 2008-01-23
Micronews HIGH 10.0
CVE-2008-0377

MicroNews allows remote attackers to bypass authentication and gain administrative privileges via a direct request to admin.php.

Mitigation only
Fix from $1,950 2008-01-22
Evilsentinel MEDIUM 5.0
CVE-2008-0351

admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter a…

Fix: after 1.0.9
Fix from $1,600 2008-01-18
Radius Server HIGH 7.8
CVE-2008-0330

Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, …

Fix: after 3.17.1
Fix from $1,950 2008-01-17
Wbr 3460a HIGH 10.0
CVE-2008-0229

The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, whi…

Mitigation only
Fix from $1,950 2008-01-10
Webmail MEDIUM 6.4
CVE-2008-0210

Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers…

No fix yet
Fix from $1,600 2008-01-10
PostgreSQL HIGH 7.2
CVE-2007-6601

The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or…

Fix: 7.3.21 / 7.4.19+
Fix from $1,950 2008-01-09
Aruba Mobility Controllers MEDIUM 6.8
CVE-2008-0150

Unspecified vulnerability in the LDAP authentication feature in Aruba Mobility Controller 2.3.6.15, 2.5.2.11, 2.5.4.25, 2.5.5.7, 3.1.1.3, and 2.4.8.1…

Fix: after 2.4.8.11-fips
Fix from $1,600 2008-01-09
Mac Os X MEDIUM 6.4
CVE-2007-5855

Mail in Apple Mac OS X 10.4.11 and 10.5.1, when an SMTP account has been set up using Account Assistant, can use plaintext authentication even when M…

Mitigation only
Fix from $1,600 2007-12-19
Mac Os X HIGH 9.4
CVE-2007-5862

Java in Mac OS X 10.4 through 10.4.11 allows remote attackers to bypass Keychain access controls and add or delete arbitrary Keychain items via a cra…

Patch available
Fix from $1,950 2007-12-18
Board MEDIUM 5.0
CVE-2007-6398

Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrary user account via the fpb_us…

Fix: after 1.2
Fix from $1,600 2007-12-17
Weblogic Mobility Server HIGH 7.5
CVE-2007-6384

Unspecified vulnerability in the Image Converter functionality in BEA WebLogic Mobility Server 3.3, 3.5, and 3.6 through 3.6 SP1 allows remote attack…

Patch available
Fix from $1,950 2007-12-15
Oas HIGH 7.1
CVE-2007-6226

The American Power Conversion (APC) AP7932 0u 30amp Switched Rack Power Distribution Unit (PDU), with rpdu 3.5.5 and aos 3.5.6, allows remote attacke…

Mitigation only
Fix from $1,950 2007-12-04
Ftp Admin HIGH 10.0
CVE-2007-6234

index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a loggedin parameter with a value …

No fix yet
Fix from $1,950 2007-12-04
Deluxebb HIGH 9.0
CVE-2007-6237

cp.php in DeluxeBB 1.09 does not verify that the membercookie parameter corresponds to the authenticated member during a profile update, which allows…

Mitigation only
Fix from $1,950 2007-12-04
Jp1 File Transmission Server MEDIUM 5.0
CVE-2007-6145

Unspecified vulnerability in Hitachi JP1/File Transmission Server/FTP 01-00 through 08-10-01 allows remote attackers to bypass authentication and "vi…

Patch available
Fix from $1,600 2007-11-27
Gnump3d MEDIUM 5.0
CVE-2007-6130

gnump3d 2.9final does not apply password protection to its plugins, which might allow remote attackers to bypass intended access restrictions.

Mitigation only
Fix from $1,600 2007-11-26
Bughotel Reservation System HIGH 10.0
CVE-2007-6011

Unspecified vulnerability in main.php of BugHotel Reservation System before 4.9.9 P3 allows remote attackers to bypass authentication and gain admini…

Fix: after 4.9.9_p2
Fix from $1,950 2007-11-16
Testlink HIGH 10.0
CVE-2007-6006

TestLink before 1.7.1 does not enforce an unspecified authorization mechanism, which has unknown impact and attack vectors.

Fix: after 1.7.0
Fix from $1,950 2007-11-15
Mac Os X MEDIUM 6.8
CVE-2007-4680

CFNetwork in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 does not properly validate certificates, which allows remote attackers to spoof trusted S…

Patch available
Fix from $1,600 2007-11-15