Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 5.0 CVE-2012-1145 spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga… Satellite Mitigation only Fix from $1,6002012-06-16 MEDIUM 5.0 CVE-2012-2606 The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display … Network Sentry Appliance Software after 5.3 Fix from $1,6002012-06-13 MEDIUM 6.4 CVE-2011-5090 GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modif… Grboard No fix yet Fix from $1,6002012-05-24 HIGH 7.6 CVE-2012-2562 The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute … Mobiletrack after 2.3.7 Fix from $1,9502012-05-22 HIGH 7.5 CVE-2011-3620EPSS 5% Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin… Qpid Mitigation only Fix from $1,9502012-05-03 MEDIUM 5.0 CVE-2011-4022 The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and ma… Intrusion Prevention System Mitigation only Fix from $1,6002012-05-03 MEDIUM 5.0 CVE-2012-0333 Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remot… Small Business Ip Phone Firmware after 7.4.9 Fix from $1,6002012-05-02 MEDIUM 5.0 CVE-2012-0335 Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attemp… Adaptive Security Appliance Software Mitigation only Fix from $1,6002012-05-02 MEDIUM 6.5 CVE-2012-2414 main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk B… Open Source Patch available Fix from $1,6002012-04-30 HIGH 10.0 CVE-2012-1799EPSS 5% The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate … Scalance S Firmware after 2.3.0 Fix from $1,9502012-04-18 HIGH 7.5 CVE-2012-1806 The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password … H0 Ecom Mitigation only Fix from $1,9502012-04-13 HIGH 10.0 CVE-2012-1808 The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not r… H0 Ecom Mitigation only Fix from $1,9502012-04-13 HIGH 7.5 CVE-2012-1840 AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login a… Ajaxplorer Patch available Fix from $1,9502012-03-22 MEDIUM 5.0 CVE-2012-1838 The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext cr… Elo Gs24m Switch Mitigation only Fix from $1,6002012-03-22 HIGH 7.9 CVE-2012-0400 EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote att… Envision Mitigation only Fix from $1,9502012-03-20 MEDIUM 5.0 CVE-2012-1256 The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account p… Easyvista after 2010 Fix from $1,6002012-02-22 MEDIUM 5.0 CVE-2012-0239 uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an admin… Advantech Webaccess after 6.0 Fix from $1,6002012-02-21 HIGH 10.0 CVE-2012-0240 GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbit… Advantech Webaccess after 6.0 Fix from $1,9502012-02-21 HIGH 9.3 CVE-2011-4508 The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C… Wincc Flexible Mitigation only Fix from $1,9502012-02-03 HIGH 10.0 CVE-2011-4514 The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels… Wincc Flexible Mitigation only Fix from $1,9502012-02-03 HIGH 7.2 CVE-2011-3463 WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera… Mac Os X Mitigation only Fix from $1,9502012-02-02 CRITICAL 9.8 CVE-2012-0931 Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a d… Modicon Quantum Plc Mitigation only Fix from $2,3002012-01-28 HIGH 10.0 CVE-2011-3478EPSS 39% The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 1… Pcanywhere Mitigation only Fix from $1,9502012-01-25 MEDIUM 6.9 CVE-2011-5054 kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi… Kcheckpass Mitigation only Fix from $1,6002012-01-06 MEDIUM 5.8 CVE-2011-5053 The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed … Wifi Protected Setup Protocol Mitigation only Fix from $1,6002012-01-06 HIGH 9.3 CVE-2011-4644EPSS 8% Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally doe… Splunk after 4.2.5 Fix from $1,9502012-01-03 MEDIUM 6.8 CVE-2011-3667 The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, … Bugzilla Mitigation only Fix from $1,6002012-01-02 HIGH 7.5 CVE-2011-3372 imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO U… Imapd after 2.4.11 Fix from $1,9502011-12-24 HIGH 10.0 CVE-2011-4860 The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates th… Quantum Ethernet Module 140noe77100 after 5.0 Fix from $1,9502011-12-17 HIGH 7.5 CVE-2011-4677 One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obta… One Click Orgs after 1.2.2 Fix from $1,9502011-12-06