Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.3 CVE-2013-1241 The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to caus… iOS Mitigation only Fix from $1,6002013-05-08 HIGH 7.5 CVE-2013-1186 Cisco Unified Computing System (UCS) 1.x before 1.4(4) and 2.x before 2.0(2m) allows remote attackers to bypass KVM authentication via a crafted auth… Unified Computing System Infrastructure And Unified Computing System Software Mitigation only Fix from $1,9502013-04-25 HIGH 10.0 CVE-2013-3268 Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors. Imanager after 2.7 Fix from $1,9502013-04-24 MEDIUM 6.4 CVE-2013-3060EPSS 6% The web console in Apache ActiveMQ before 5.8.0 does not require authentication, which allows remote attackers to obtain sensitive information or cau… Activemq after 5.7.0 Fix from $1,6002013-04-21 MEDIUM 5.0 CVE-2013-0282 OpenStack Keystone Grizzly before 2013.1, Folsom 2012.1.3 and earlier, and Essex does not properly check if the (1) user, (2) tenant, or (3) domain i… Keystone after 2012.2.4 Fix from $1,6002013-04-12 HIGH 7.5 CVE-2013-0314 The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, whi… Jboss Enterprise Portal Platform Mitigation only Fix from $1,9502013-04-12 HIGH 7.8 CVE-2013-1150 The authentication-proxy implementation on Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31),… Adaptive Security Appliance Software Mitigation only Fix from $1,9502013-04-11 HIGH 7.8 CVE-2013-1155 The auth-proxy functionality in Cisco Firewall Services Module (FWSM) software 3.1 and 3.2 before 3.2(20.1), 4.0 before 4.0(15.2), and 4.1 before 4.1… Firewall Services Module Software Mitigation only Fix from $1,9502013-04-11 HIGH 7.5 CVE-2013-2741 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, whic… Backupbuddy No fix yet Fix from $1,9502013-04-02 HIGH 7.5 CVE-2013-2743 importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via … Backupbuddy No fix yet Fix from $1,9502013-04-02 HIGH 10.0 CVE-2013-1080EPSS 77% The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform authentication for zenworks/js… Zenworks Configuration Management Mitigation only Fix from $1,9502013-03-29 HIGH 9.3 CVE-2013-0935 EMC Smarts Network Configuration Manager (NCM) before 9.2 does not require authentication for all Java RMI method calls, which allows remote attacker… Smarts Network Configuration Manager after 9.1 Fix from $1,9502013-03-28 MEDIUM 6.8 CVE-2013-0258 The Google Authenticator login (ga_login) module 7.x before 7.x-1.3 for Drupal, when multi-factor authentication is enabled, allows remote attackers … Ga Login Patch available Fix from $1,6002013-03-27 HIGH 8.5 CVE-2013-0487 The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration detai… Lotus Domino Mitigation only Fix from $1,9502013-03-27 MEDIUM 6.8 CVE-2013-1865 OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remot… Ubuntu Linux Mitigation only Fix from $1,6002013-03-22 MEDIUM 6.8 CVE-2012-4446 The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking t… Qpid after 0.20 Fix from $1,6002013-03-14 MEDIUM 5.8 CVE-2012-5633EPSS 8% The URIMappingInterceptor in Apache CXF before 2.5.8, 2.6.x before 2.6.5, and 2.7.x before 2.7.2, when using the WSS4JInInterceptor, bypasses WS-Secu… Cxf after 2.5.7 Fix from $1,6002013-03-12 MEDIUM 5.0 CVE-2013-0239 Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote att… Cxf after 2.5.8 Fix from $1,6002013-03-12 MEDIUM 5.0 CVE-2012-4066 The internal message protocol for Walrus in Eucalyptus 3.2.0 and earlier does not require signatures for unspecified request headers, which allows at… Eucalyptus after 3.2.0 Fix from $1,6002013-03-08 HIGH 7.5 CVE-2013-0910 Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization o… Chrome after 25.0.1364.126 Fix from $1,9502013-03-05 HIGH 7.1 CVE-2013-1134 The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not req… Unified Communications Manager Mitigation only Fix from $1,9502013-02-27 MEDIUM 5.0 CVE-2012-6274EPSS 47% BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under… Bigant Im Message Server Mitigation only Fix from $1,6002013-02-24 MEDIUM 5.0 CVE-2012-5952 IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.6, and 8.0 before 8.0.0.2 does not validate Basic Authentication credentials befor… Websphere Message Broker Mitigation only Fix from $1,6002013-02-20 HIGH 7.5 CVE-2012-6354 The management GUI on the IBM SAN Volume Controller and Storwize V7000 6.x before 6.4.1.3 allows remote attackers to bypass authentication and obtain… San Volume Controller Software Mitigation only Fix from $1,9502013-02-19 HIGH 10.0 CVE-2013-1405 VMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 bef… Vcenter Server Mitigation only Fix from $1,9502013-02-15 MEDIUM 6.8 CVE-2012-0874EPSS 14% The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (E… Jboss Enterprise Application Platform after 5.3.0 Fix from $1,6002013-02-05 CRITICAL 9.8 CVE-2012-6437EPSS 8% The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth… Controllogix Controllers after 1400 Fix from $2,3002013-01-24 HIGH 7.5 CVE-2013-0209EPSS 45% lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration fun… Movable Type Patch available Fix from $1,9502013-01-23 MEDIUM 5.0 CVE-2013-0759 Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 a… Firefox 2.15 / 10.0.12+ Fix from $1,6002013-01-13 CRITICAL 9.8 CVE-2013-0625 KEVEPSS 94% Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbi… Coldfusion Mitigation only Fix from $2,3002013-01-09