Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.1 CVE-2012-4545 The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotia… Elinks Mitigation only Fix from $1,6002013-01-03 HIGH 7.5 CVE-2012-4688 The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser… Oplynx after 2.01.8 Fix from $1,9502012-12-31 MEDIUM 6.4 CVE-2012-5930EPSS 7% The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for… Privileged User Manager No fix yet Fix from $1,6002012-12-24 HIGH 10.0 CVE-2012-3002 The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or… H.264 Hi3510\/11\/12 Ip Camera Mitigation only Fix from $1,9502012-12-21 HIGH 9.3 CVE-2012-6066EPSS 40% freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client w… Freesshd after 1.2.6 Fix from $1,9502012-12-04 HIGH 10.0 CVE-2012-6067 freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH cl… Freeftpd after 1.0.11 Fix from $1,9502012-12-04 HIGH 9.3 CVE-2012-5975EPSS 36% The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2… Tectia Server No fix yet Fix from $1,9502012-12-04 HIGH 9.3 CVE-2012-4614 The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which all… It Operations Intelligence after 9.0 Fix from $1,9502012-11-27 MEDIUM 5.0 CVE-2012-2437 cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via … Ar Web Content Manager No fix yet Fix from $1,6002012-11-26 MEDIUM 6.8 CVE-2011-4085 The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, … Jboss Enterprise Application Platform after 5.2.0 Fix from $1,6002012-11-23 HIGH 10.0 CVE-2012-5864 These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within t… Sinapsi Firmware after 2.0.2870 Fix from $1,9502012-11-23 HIGH 7.8 CVE-2012-5758 The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int… Websphere Datapower Xc10 Appliance Mitigation only Fix from $1,9502012-11-23 MEDIUM 5.0 CVE-2012-5886EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5887EPSS 12% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly… Tomcat 5.5.36 / 6.0.36+ Fix from $1,6002012-11-17 MEDIUM 6.9 CVE-2012-4613 EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user accou… Rsa Data Protection Manager Appliance Mitigation only Fix from $1,6002012-11-16 MEDIUM 5.5 CVE-2012-4021 MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accoun… Kintai Kanri after 4.0.9 Fix from $1,6002012-11-08 MEDIUM 5.0 CVE-2012-3315 The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Busin… Tivoli Federated Identity Manager after 6.2.2 Fix from $1,6002012-11-08 HIGH 7.1 CVE-2012-4659 The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Modul… Adaptive Security Appliance Software Mitigation only Fix from $1,9502012-10-29 MEDIUM 5.8 CVE-2012-4418EPSS 6% Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack." Axis2 No fix yet Fix from $1,6002012-10-09 MEDIUM 6.4 CVE-2012-5351EPSS 5% Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur… Axis2 Mitigation only Fix from $1,6002012-10-09 MEDIUM 5.8 CVE-2012-5352 Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a S… Java Open Single Sign On Project Home Mitigation only Fix from $1,6002012-10-09 MEDIUM 5.8 CVE-2012-5353 Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature el… Openathens Service Provider Mitigation only Fix from $1,6002012-10-09 HIGH 7.5 CVE-2012-4456 The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-… Keystone 2012.1.2+ Fix from $1,9502012-10-09 MEDIUM 6.8 CVE-2012-5309 servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it… Lotus Notes Traveler No fix yet Fix from $1,6002012-10-08 HIGH 7.5 CVE-2012-1602 user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1. Nextbbs No fix yet Fix from $1,9502012-10-01 MEDIUM 6.4 CVE-2012-3492 The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories eve… Condor Mitigation only Fix from $1,6002012-09-28 HIGH 8.5 CVE-2012-2287 The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an… Rsa Authentication Agent Mitigation only Fix from $1,9502012-09-25 MEDIUM 6.4 CVE-2012-3137EPSS 31% The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtai… Database Server Patch available Fix from $1,6002012-09-21 MEDIUM 5.0 CVE-2012-3721 Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows at… Mac Os X after 10.7.4 Fix from $1,6002012-09-20 MEDIUM 6.8 CVE-2012-5003 nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote a… Nx Web Companion after 3.5.0-2 Fix from $1,6002012-09-19