Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Mac Os X HIGH 7.2
CVE-2007-4693

The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen …

Patch available
Fix from $1,950 2007-11-15
Bti Tracker MEDIUM 6.8
CVE-2007-5987

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a di…

Fix: after 1.4.4
Fix from $1,600 2007-11-15
Bti Tracker HIGH 7.5
CVE-2007-5988

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary user…

Fix: after 1.4.4
Fix from $1,950 2007-11-15
Ruby MEDIUM 5.0
CVE-2007-5770

The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the common…

Patch available
Fix from $1,600 2007-11-14
Jbc Explorer MEDIUM 6.8
CVE-2007-5913EPSS 7%

dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.ph…

Fix: after 7.20_rc1
Fix from $1,600 2007-11-10
Geronimo HIGH 7.5
CVE-2007-5797

SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…

Mitigation only
Fix from $1,950 2007-11-03
Motorola Phone Adapter Vt2142 Vd HIGH 10.0
CVE-2007-5791

The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows rem…

Mitigation only
Fix from $1,950 2007-11-01
Php Agtc Membership System HIGH 7.5
CVE-2007-5752

adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts vi…

Mitigation only
Fix from $1,950 2007-10-31
Mldonkey Ebuild MEDIUM 6.8
CVE-2007-5714

The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote a…

Fix: after 2.9.0
Fix from $1,600 2007-10-30
Basic Analysis And Security Engine HIGH 7.5
CVE-2007-5578

Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass…

Patch available
Fix from $1,950 2007-10-18
Select Identity HIGH 10.0
CVE-2007-5391

Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access …

No fix yet
Fix from $1,950 2007-10-12
Speedtouch 7g Router HIGH 10.0
CVE-2007-5383

The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentic…

Fix: after 6.2.6.b
Fix from $1,950 2007-10-12
Lightblog MEDIUM 6.5
CVE-2007-5374

cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticat…

No fix yet
Fix from $1,600 2007-10-11
Brightstor Arcserve Backup Laptops Desktops HIGH 10.0
CVE-2007-5006EPSS 21%

Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer…

Patch available
Fix from $1,950 2007-10-01
Java System Access Manager HIGH 7.5
CVE-2007-5152

Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a cont…

Mitigation only
Fix from $1,950 2007-10-01
Urchin MEDIUM 5.0
CVE-2007-5113

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified …

Fix: after 5.7.03
Fix from $1,600 2007-09-26
Geronimo MEDIUM 5.0
CVE-2007-5085

Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…

Mitigation only
Fix from $1,600 2007-09-26
Netsupport Manager Client HIGH 10.0
CVE-2007-5057

NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport…

Mitigation only
Fix from $1,950 2007-09-24
Hp Ux HIGH 9.0
CVE-2007-5008

The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileg…

Mitigation only
Fix from $1,950 2007-09-20
Video Surveillance Ip Gateway Encoder Decoder HIGH 10.0
CVE-2007-4747

The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/I…

Fix: after 1.23.7
Fix from $1,950 2007-09-06
Geronimo HIGH 10.0
CVE-2007-4548

The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…

Patch available
Fix from $1,950 2007-08-27
Ampache MEDIUM 6.8
CVE-2007-4438

Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 3.3.3.4
Fix from $1,600 2007-08-20
Olatedownload HIGH 9.3
CVE-2007-4419

Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication coo…

No fix yet
Fix from $1,950 2007-08-18
Commons HIGH 8.5
CVE-2007-4364

Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to…

Fix: after 2.2
Fix from $1,950 2007-08-15
Mambo Open Source HIGH 9.3
CVE-2007-4203

Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.

Mitigation only
Fix from $1,950 2007-08-08
Securityreporter CRITICAL 9.8
CVE-2007-4043

file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a nam…

Fix: after 4.6.3
Fix from $2,300 2007-07-27
Virtual Hosting Control System MEDIUM 6.8
CVE-2007-3988

Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting…

Fix: after 2.4.7.1
Fix from $1,600 2007-07-25
Zen Cart HIGH 8.5
CVE-2007-3597

Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.

Fix: after 1.3.7
Fix from $1,950 2007-07-06
Mac Os X HIGH 7.2
CVE-2007-3184

Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System P…

Patch available
Fix from $1,950 2007-06-12
Ingate Firewall MEDIUM 5.0
CVE-2007-3177

Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.

Fix: after 4.5.1
Fix from $1,600 2007-06-11