Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.4 CVE-2012-4926 approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activation of administrators via t… Img Pals Photo Host No fix yet Fix from $1,6002012-09-15 MEDIUM 5.0 CVE-2012-2983EPSS 20% file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote… Webmin after 1.590 Fix from $1,6002012-09-11 HIGH 7.5 CVE-2012-4392 index.php in ownCloud 4.0.7 does not properly validate the oc_token cookie, which allows remote attackers to bypass authentication via a crafted oc_t… Owncloud Server Patch available Fix from $1,9502012-09-05 MEDIUM 5.0 CVE-2012-4741 The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment ext… Packetfence after 3.2.0 Fix from $1,6002012-08-31 MEDIUM 6.8 CVE-2012-2285 EMC Cloud Tiering Appliance (aka CTA, formerly FMA) 9.0 and earlier, and Cloud Tiering Appliance Virtual Edition (CTA/VE) 9.0 and earlier, allows rem… Cloud Tiering Appliance Virtual Edition after 9.0 Fix from $1,6002012-08-29 MEDIUM 5.0 CVE-2012-3467EPSS 6% Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remo… Qpid after 0.16 Fix from $1,6002012-08-27 HIGH 10.0 CVE-2012-3416EPSS 5% Condor before 7.8.2 allows remote attackers to bypass host-based authentication and execute actions such as ALLOW_ADMINISTRATOR or ALLOW_WRITE by con… Condor after 7.8.1 Fix from $1,9502012-08-25 HIGH 7.5 CVE-2012-4595 McAfee Email and Web Security (EWS) 5.5 through Patch 6 and 5.6 through Patch 3, and McAfee Email Gateway (MEG) 7.0.0 and 7.0.1, allows remote attack… Email And Web Security Mitigation only Fix from $1,9502012-08-22 HIGH 10.0 CVE-2012-4599 McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBo… Smartfilter Administration after 4.2.1 Fix from $1,9502012-08-22 HIGH 7.5 CVE-2011-5100 The web interface in McAfee Firewall Reporter before 5.1.0.13 does not properly implement cookie authentication, which allows remote attackers to obt… Firewall Reporter after 5.1.0.6 Fix from $1,9502012-08-22 MEDIUM 6.8 CVE-2012-4581 McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, does not disabl… Email And Web Security Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.5 CVE-2009-5116 McAfee LinuxShield 1.5.1 and earlier does not properly implement client authentication, which allows remote authenticated users to obtain Admin acces… Linuxshield after 1.5.1 Fix from $1,6002012-08-22 MEDIUM 5.0 CVE-2012-2132 libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers … Libsoup Mitigation only Fix from $1,6002012-08-20 MEDIUM 5.0 CVE-2012-3024 Tridium Niagara AX Framework through 3.6 uses predictable values for (1) session IDs and (2) keys, which might allow remote attackers to bypass authe… Niagara Ax after 3.6 Fix from $1,6002012-08-16 MEDIUM 6.4 CVE-2012-3472 The email API in application/libraries/api/MY_Email_Api_Object.php in the Ushahidi Platform before 2.5 does not require authentication, which allows … Ushahidi Platform after 2.4.1 Fix from $1,6002012-08-12 MEDIUM 6.4 CVE-2012-3473 The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allow… Ushahidi Platform after 2.4.1 Fix from $1,6002012-08-12 MEDIUM 5.0 CVE-2012-2963 The administrative interface in the embedded web server on the BreakingPoint Storm appliance before 3.0 does not require authentication for the gwt/B… Breakingpoint Storm Appliance Ctm after 2.0 Fix from $1,6002012-08-12 MEDIUM 5.0 CVE-2012-3424 The decode_credentials method in actionpack/lib/action_controller/metal/http_authentication.rb in Ruby on Rails 3.x before 3.0.16, 3.1.x before 3.1.7… Rails Mitigation only Fix from $1,6002012-08-08 MEDIUM 5.0 CVE-2012-2626EPSS 44% cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which… Scrutinizer 9.5.0+ Fix from $1,6002012-07-31 MEDIUM 5.0 CVE-2012-3884 AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attackers to… Airdroid No fix yet Fix from $1,6002012-07-26 HIGH 7.5 CVE-2012-3885 The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to obtain ac… Airdroid No fix yet Fix from $1,9502012-07-26 MEDIUM 5.0 CVE-2012-3356 The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote att… Viewvc after 1.1.14 Fix from $1,6002012-07-22 HIGH 10.0 CVE-2012-2974 The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request … Smc8024l2 Switch Mitigation only Fix from $1,9502012-07-19 MEDIUM 5.0 CVE-2012-2351 The default configuration of the auth/saml plugin in Mahara before 1.4.2 sets the "Match username attribute to Remote username" option to false, whic… Debian Linux after 1.4.1 Fix from $1,6002012-07-12 MEDIUM 5.4 CVE-2012-0301 Session fixation vulnerability in Brightmail Control Center in Symantec Message Filter 6.3 allows remote attackers to hijack web sessions via unspeci… Message Filter after 6.3 Fix from $1,6002012-07-05 MEDIUM 6.8 CVE-2012-2281 EMC RSA Access Manager Server 6.x before 6.1 SP4 and RSA Access Manager Agent do not properly validate session tokens after a logout, which might all… Access Manager Agent Mitigation only Fix from $1,6002012-07-05 HIGH 7.5 CVE-2012-1123 The mci_check_login function in api/soap/mc_api.php in the SOAP API in MantisBT before 1.2.9 allows remote attackers to bypass authentication via a n… Mantisbt after 1.2.8 Fix from $1,9502012-06-29 HIGH 7.5 CVE-2012-2388 The GMP Plugin in strongSwan 4.2.0 through 4.6.3 allows remote attackers to bypass authentication via a (1) empty or (2) zeroed RSA signature, aka "R… Strongswan Mitigation only Fix from $1,9502012-06-27 MEDIUM 5.1 CVE-2012-2122EPSS 97% sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12… MySQL Patch available Fix from $1,6002012-06-26 HIGH 7.5 CVE-2009-0695EPSS 69% hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access… Wyse Device Manager No fix yet Fix from $1,9502012-06-19