Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.0 CVE-2013-1443 The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attack… Django Patch available Fix from $1,6002013-09-23 MEDIUM 6.8 CVE-2013-5119 Zimbra Collaboration Suite (ZCS) 6.0.16 and earlier allows man-in-the-middle attackers to obtain access by sniffing the network and replaying the ZM_… Zimbra Collaboration Suite after 6.0.16 Fix from $1,6002013-09-23 HIGH 7.8 CVE-2013-3473 The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of … Prime Central For Hosted Collaboration Solution Assurance after 9.1 Fix from $1,9502013-09-20 HIGH 7.8 CVE-2013-3613EPSS 7% Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a repl… Dvr0404hd A Mitigation only Fix from $1,9502013-09-17 MEDIUM 5.4 CVE-2013-3039 IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors. Rational Requirements Composer after 4.0.3 Fix from $1,6002013-09-12 HIGH 10.0 CVE-2012-6603 The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authe… Pan Os after 3.1.11 Fix from $1,9502013-08-31 HIGH 9.3 CVE-2013-3466EPSS 5% The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled,… Secure Access Control Server after 4.2.1.15.10 Fix from $1,9502013-08-29 HIGH 7.6 CVE-2013-3586EPSS 11% Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie. Smart Viewer Mitigation only Fix from $1,9502013-08-28 MEDIUM 6.9 CVE-2013-4958 Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended wor… Puppet Enterprise after 3.0.0 Fix from $1,6002013-08-20 MEDIUM 5.8 CVE-2013-2993 IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allo… Websphere Commerce Mitigation only Fix from $1,6002013-08-01 MEDIUM 5.0 CVE-2013-2056 The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which al… Satellite Mitigation only Fix from $1,6002013-07-31 HIGH 9.0 CVE-2013-3430EPSS 8% Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspe… Video Surveillance Manager after 6.3.3 Fix from $1,9502013-07-25 HIGH 7.8 CVE-2013-3431EPSS 9% Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attacker… Video Surveillance Manager after 6.3.3 Fix from $1,9502013-07-25 MEDIUM 5.8 CVE-2013-3656 Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of … Cybozu Office after 9.1.0 Fix from $1,6002013-07-20 MEDIUM 6.2 CVE-2013-4874 The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a c… Wireless Network Extender Mitigation only Fix from $1,6002013-07-18 MEDIUM 6.2 CVE-2013-4875 The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and … Wireless Network Extender Mitigation only Fix from $1,6002013-07-18 HIGH 10.0 CVE-2013-4782EPSS 26% The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka c… Bmc Mitigation only Fix from $1,9502013-07-08 HIGH 10.0 CVE-2013-4783 The Dell iDRAC6 with firmware 1.x before 1.92 and 2.x and 3.x before 3.42, and iDRAC7 with firmware before 1.23.23, allows remote attackers to bypass… Idrac6 Bmc Mitigation only Fix from $1,9502013-07-08 HIGH 10.0 CVE-2013-4784EPSS 50% The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using c… Integrated Lights Out Bmc Mitigation only Fix from $1,9502013-07-08 HIGH 7.1 CVE-2013-3581 ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information v… Wixfmr 111 Mitigation only Fix from $1,9502013-07-02 HIGH 9.3 CVE-2013-4731 ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to execute arbitrary commands via… Wixfmr 111 No fix yet Fix from $1,9502013-06-30 MEDIUM 6.8 CVE-2013-2067EPSS 7% java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x befor… Tomcat Patch available Fix from $1,6002013-06-01 MEDIUM 5.0 CVE-2013-1209 The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Ne… Nx Os Mitigation only Fix from $1,6002013-05-29 MEDIUM 5.0 CVE-2013-1211 Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communica… Nx Os Mitigation only Fix from $1,6002013-05-29 MEDIUM 5.0 CVE-2013-2954 The login page in the Console in IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 does not limit the num… Infosphere Optim Data Growth For Oracle E Business Suite Mitigation only Fix from $1,6002013-05-27 MEDIUM 6.0 CVE-2013-2059 OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana does not immediately revoke the authentication token w… Keystone No fix yet Fix from $1,6002013-05-21 MEDIUM 5.0 CVE-2013-1188 Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a den… Unified Communications Manager Mitigation only Fix from $1,6002013-05-16 MEDIUM 6.8 CVE-2013-1200 Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, ak… Secure Access Control System Mitigation only Fix from $1,6002013-05-16 HIGH 7.5 CVE-2013-1337EPSS 21% Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication i… .net Framework Mitigation only Fix from $1,9502013-05-15 MEDIUM 5.8 CVE-2013-0937 Session fixation vulnerability in EMC Documentum Webtop before 6.7 SP2, Documentum WDK before 6.7 SP2, Documentum Taskspace before 6.7 SP2, and Docum… Documentum Records Manager Mitigation only Fix from $1,6002013-05-10