Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.4
CVE-2012-4926
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via t…
Img Pals Photo Host
No fix yet
MEDIUM 5.0
CVE-2012-2983EPSS 20%
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote…
Webmin
after 1.590
HIGH 7.5
CVE-2012-4392
index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_t…
Owncloud Server
Patch available
MEDIUM 5.0
CVE-2012-4741
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment ext…
Packetfence
after 3.2.0
MEDIUM 6.8
CVE-2012-2285
EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows rem…
Cloud Tiering Appliance Virtual Edition
after 9.0
MEDIUM 5.0
CVE-2012-3467EPSS 6%
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo…
Qpid
after 0.16
HIGH 10.0
CVE-2012-3416EPSS 5%
Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by con…
Condor
after 7.8.1
HIGH 7.5
CVE-2012-4595
McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack…
Email And Web Security
Mitigation only
HIGH 10.0
CVE-2012-4599
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBo…
Smartfilter Administration
after 4.2.1
HIGH 7.5
CVE-2011-5100
The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obt…
Firewall Reporter
after 5.1.0.6
MEDIUM 6.8
CVE-2012-4581
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl…
Email And Web Security
Mitigation only
MEDIUM 6.5
CVE-2009-5116
McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin acces…
Linuxshield
after 1.5.1
MEDIUM 5.0
CVE-2012-2132
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers …
Libsoup
Mitigation only
MEDIUM 5.0
CVE-2012-3024
Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authe…
Niagara Ax
after 3.6
MEDIUM 6.4
CVE-2012-3472
The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows …
Ushahidi Platform
after 2.4.1
MEDIUM 6.4
CVE-2012-3473
The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allow…
Ushahidi Platform
after 2.4.1
MEDIUM 5.0
CVE-2012-2963
The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/B…
Breakingpoint Storm Appliance Ctm
after 2.0
MEDIUM 5.0
CVE-2012-3424
The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7…
Rails
Mitigation only
MEDIUM 5.0
CVE-2012-2626EPSS 44%
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…
Scrutinizer
9.5.0+
MEDIUM 5.0
CVE-2012-3884
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to…
Airdroid
No fix yet
HIGH 7.5
CVE-2012-3885
The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain ac…
Airdroid
No fix yet
MEDIUM 5.0
CVE-2012-3356
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote att…
Viewvc
after 1.1.14
HIGH 10.0
CVE-2012-2974
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request …
Smc8024l2 Switch
Mitigation only
MEDIUM 5.0
CVE-2012-2351
The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, whic…
Debian Linux
after 1.4.1
MEDIUM 5.4
CVE-2012-0301
Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspeci…
Message Filter
after 6.3
MEDIUM 6.8
CVE-2012-2281
EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might all…
Access Manager Agent
Mitigation only
HIGH 7.5
CVE-2012-1123
The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a n…
Mantisbt
after 1.2.8
HIGH 7.5
CVE-2012-2388
The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "R…
Strongswan
Mitigation only
MEDIUM 5.1
CVE-2012-2122EPSS 97%
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12…
MySQL
Patch available
HIGH 7.5
CVE-2009-0695EPSS 69%
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access…
Wyse Device Manager
No fix yet