Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.8 CVE-2014-3781 The dcXmlRpc::setUser method in nc/core/class.dc.xmlrpc.php in Dotclear before 2.6.3 allows remote attackers to bypass authentication via an empty pa… Dotclear after 2.6.2 Fix from $1,6002014-06-11 MEDIUM 5.8 CVE-2014-3944 The Authentication component in TYPO3 6.2.0 before 6.2.3 does not properly invalidate timed out user sessions, which allows remote attackers to bypas… TYPO3 Mitigation only Fix from $1,6002014-06-03 MEDIUM 5.0 CVE-2013-0191 libpam-pgsql (aka pam_pgsql) 0.7 does not properly handle a NULL value returned by the password search query, which allows remote attackers to bypass… Libpam Pgsql Patch available Fix from $1,6002014-06-03 MEDIUM 5.0 CVE-2013-6470 The default configuration in the standalone controller quickstack manifest in openstack-foreman-installer, as used in Red Hat Enterprise Linux OpenSt… Openstack Mitigation only Fix from $1,6002014-06-02 HIGH 7.5 CVE-2014-3780 Unspecified vulnerability in Citrix VDI-In-A-Box 5.3.x before 5.3.8 and 5.4.x before 5.4.4 allows remote attackers to bypass authentication via unspe… Vdi In A Box Mitigation only Fix from $1,9502014-05-30 HIGH 7.5 CVE-2013-6788 The Bitrix e-Store module before 14.0.1 for Bitrix Site Manager uses sequential values for the BITRIX_SM_SALE_UID cookie, which makes it easier for r… Bitrix E Store Module after 14.0.0 Fix from $1,9502014-05-30 MEDIUM 5.0 CVE-2013-4178 The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replay… Ga Login Mitigation only Fix from $1,6002014-05-29 MEDIUM 5.0 CVE-2012-6452 Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests dependi… Email Firewall after 6.5.0 Fix from $1,6002014-05-27 MEDIUM 6.8 CVE-2014-0214 login/token.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 creates a MoodleMobile web-service token wi… Moodle after 2.3.11 Fix from $1,6002014-05-27 MEDIUM 5.0 CVE-2013-2756EPSS 6% Apache CloudStack 4.0.0 before 4.0.2 and Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C allows remote attackers to bypa… Cloudstack Patch available Fix from $1,6002014-05-23 HIGH 8.3 CVE-2014-2938 Hanvon FaceID before 1.007.110 does not require authentication, which allows remote attackers to modify access-control and attendance-tracking data v… Faceid F810 Firmware after 1.007.109 Fix from $1,9502014-05-22 HIGH 7.5 CVE-2013-6765EPSS 7% OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands … Openvas Manager Mitigation only Fix from $1,9502014-05-19 HIGH 7.5 CVE-2013-6766 OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP com… Openvas Administrator Mitigation only Fix from $1,9502014-05-19 MEDIUM 6.8 CVE-2013-6806 OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a cr… Exceed Ondemand Mitigation only Fix from $1,6002014-05-19 MEDIUM 6.8 CVE-2013-7379 The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote at… Tomato after 0.0.5 Fix from $1,6002014-05-16 HIGH 7.6 CVE-2014-0643 EMC RSA NetWitness before 9.8.5.19 and RSA Security Analytics before 10.2.4 and 10.3.x before 10.3.2, when Kerberos PAM is enabled, do not require a … Rsa Netwitness 9.8.5.19 / 10.2.4+ Fix from $1,9502014-05-16 MEDIUM 5.0 CVE-2014-3430 Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attac… Dovecot Patch available Fix from $1,6002014-05-14 MEDIUM 5.5 CVE-2013-4471 The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, w… Horizon 2013.2+ Fix from $1,6002014-05-14 HIGH 7.5 CVE-2013-4552 lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via… Drupalauth after 1.2.1 Fix from $1,9502014-05-13 MEDIUM 6.8 CVE-2013-4580 GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impe… GitLab after 5.4.1 Fix from $1,6002014-05-12 HIGH 9.3 CVE-2013-4772 D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a d… Dir 826l Wireless N600 Cloud Router Firmware No fix yet Fix from $1,9502014-05-12 MEDIUM 6.8 CVE-2014-0090 Session fixation vulnerability in Foreman before 1.4.2 allows remote attackers to hijack web sessions via the session id cookie. Foreman after 1.4.1 Fix from $1,6002014-05-08 MEDIUM 6.8 CVE-2014-2181 Cisco Adaptive Security Appliance (ASA) Software allows remote authenticated users to read files by sending a crafted URL to the HTTP server, as demo… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-05-07 HIGH 7.5 CVE-2014-3139 recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by setting the auth parameter to … Enterprise Backup No fix yet Fix from $1,9502014-05-02 MEDIUM 6.8 CVE-2013-7302 Session fixation vulnerability in the Ubercart module 6.x-2.x before 6.x-2.13 and 7.x-3.x before 7.x-3.6 for Drupal, when the "Log in new customers a… Ubercart Patch available Fix from $1,6002014-04-29 HIGH 9.3 CVE-2014-0760 The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented acc… Codesys Runtime System Mitigation only Fix from $1,9502014-04-25 HIGH 9.3 CVE-2014-0769 The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication… Softmotion Mitigation only Fix from $1,9502014-04-25 HIGH 7.5 CVE-2014-0188 The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remot… Openshift after 2.0.5 Fix from $1,9502014-04-24 MEDIUM 5.0 CVE-2012-4658 The ios-authproxy implementation in Cisco IOS before 15.1(1)SY3 allows remote attackers to cause a denial of service (webauth and HTTP service outage… iOS after 15.1 Fix from $1,6002014-04-23 MEDIUM 6.4 CVE-2012-5032 The Flex-VPN load-balancing feature in the ipsec-ikev2 implementation in Cisco IOS before 15.1(1)SY3 does not require authentication, which allows re… iOS after 15.1 Fix from $1,6002014-04-23