Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.1
CVE-2012-4545
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotia…
Elinks
Mitigation only
HIGH 7.5
CVE-2012-4688
The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser…
Oplynx
after 2.01.8
MEDIUM 6.4
CVE-2012-5930EPSS 7%
The pa_modify_accounts function in auth.dll in unifid.exe in NetIQ Privileged User Manager 2.3.x before 2.3.1 HF2 does not require authentication for…
Privileged User Manager
No fix yet
HIGH 10.0
CVE-2012-3002
The web interface on (1) Foscam and (2) Wansview IP cameras allows remote attackers to bypass authentication, and perform administrative functions or…
H.264 Hi3510\/11\/12 Ip Camera
Mitigation only
HIGH 9.3
CVE-2012-6066EPSS 40%
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client w…
Freesshd
after 1.2.6
HIGH 10.0
CVE-2012-6067
freeFTPd.exe in freeFTPd through 1.0.11 allows remote attackers to bypass authentication via a crafted SFTP session, as demonstrated by an OpenSSH cl…
Freeftpd
after 1.0.11
HIGH 9.3
CVE-2012-5975EPSS 36%
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2…
Tectia Server
No fix yet
HIGH 9.3
CVE-2012-4614
The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which all…
It Operations Intelligence
after 9.0
MEDIUM 5.0
CVE-2012-2437
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via …
Ar Web Content Manager
No fix yet
MEDIUM 6.8
CVE-2011-4085
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, …
Jboss Enterprise Application Platform
after 5.2.0
HIGH 10.0
CVE-2012-5864
These Sinapsi devices
do not check if users that visit pages within the device have properly
authenticated. By directly visiting the pages within t…
Sinapsi Firmware
after 2.0.2870
HIGH 7.8
CVE-2012-5758
The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 does not require authentication for an unspecified int…
Websphere Datapower Xc10 Appliance
Mitigation only
MEDIUM 5.0
CVE-2012-5886EPSS 9%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches informatio…
Tomcat
Mitigation only
MEDIUM 5.0
CVE-2012-5887EPSS 12%
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 does not properly…
Tomcat
5.5.36 / 6.0.36+
MEDIUM 6.9
CVE-2012-4613
EMC RSA Data Protection Manager Appliance 2.7.x and 3.x before 3.2.1 does not properly restrict the number of authentication attempts by a user accou…
Rsa Data Protection Manager Appliance
Mitigation only
MEDIUM 5.5
CVE-2012-4021
MosP kintai kanri before 4.1.0 does not properly perform authentication, which allows remote authenticated users to impersonate arbitrary user accoun…
Kintai Kanri
after 4.0.9
MEDIUM 5.0
CVE-2012-3315
The Java servlets in the management console in IBM Tivoli Federated Identity Manager (TFIM) through 6.2.2 and Tivoli Federated Identity Manager Busin…
Tivoli Federated Identity Manager
after 6.2.2
HIGH 7.1
CVE-2012-4659
The AAA functionality in the IPv4 SSL VPN implementations on Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services Modul…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 5.8
CVE-2012-4418EPSS 6%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."
Axis2
No fix yet
MEDIUM 6.4
CVE-2012-5351EPSS 5%
Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signatur…
Axis2
Mitigation only
MEDIUM 5.8
CVE-2012-5352
Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a S…
Java Open Single Sign On Project Home
Mitigation only
MEDIUM 5.8
CVE-2012-5353
Eduserv OpenAthens SP 2.0 for Java allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature el…
Openathens Service Provider
Mitigation only
HIGH 7.5
CVE-2012-4456
The (1) OS-KSADM/services and (2) tenant APIs in OpenStack Keystone Essex before 2012.1.2 and Folsom before folsom-2 do not properly validate X-Auth-…
Keystone
2012.1.2+
MEDIUM 6.8
CVE-2012-5309
servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it…
Lotus Notes Traveler
No fix yet
HIGH 7.5
CVE-2012-1602
user.php in NextBBS 0.6 allows remote attackers to bypass authentication and gain administrator access by setting the userkey cookie to 1.
Nextbbs
No fix yet
MEDIUM 6.4
CVE-2012-3492
The filesystem authentication (condor_io/condor_auth_fs.cpp) in Condor 7.6.x before 7.6.10 and 7.8.x before 7.8.4 uses authentication directories eve…
Condor
Mitigation only
HIGH 8.5
CVE-2012-2287
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an…
Rsa Authentication Agent
Mitigation only
MEDIUM 6.4
CVE-2012-3137EPSS 31%
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to obtai…
Database Server
Patch available
MEDIUM 5.0
CVE-2012-3721
Profile Manager in Apple Mac OS X before 10.7.5 does not properly perform authentication for the Device Management private interface, which allows at…
Mac Os X
after 10.7.4
MEDIUM 6.8
CVE-2012-5003
nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote a…
Nx Web Companion
after 3.5.0-2