Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.0
CVE-2012-1145
spacewalk-backend in Red Hat Network Satellite 5.4 on Red Hat Enterprise Linux 6 does not properly authorize or authenticate uploads to the NULL orga…
Satellite
Mitigation only
MEDIUM 5.0
CVE-2012-2606
The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display …
Network Sentry Appliance Software
after 5.3
MEDIUM 6.4
CVE-2011-5090
GR Board (aka grboard) 1.8.6.5 Community Edition does not require authentication for certain database actions, which allows remote attackers to modif…
Grboard
No fix yet
HIGH 7.6
CVE-2012-2562
The Xelex MobileTrack application 2.3.7 and earlier for Android does not verify the origin of SMS commands, which allows remote attackers to execute …
Mobiletrack
after 2.3.7
HIGH 7.5
CVE-2011-3620EPSS 5%
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messagin…
Qpid
Mitigation only
MEDIUM 5.0
CVE-2011-4022
The sensor in Cisco Intrusion Prevention System (IPS) 7.0 and 7.1 allows remote attackers to cause a denial of service (file-handle exhaustion and ma…
Intrusion Prevention System
Mitigation only
MEDIUM 5.0
CVE-2012-0333
Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remot…
Small Business Ip Phone Firmware
after 7.4.9
MEDIUM 5.0
CVE-2012-0335
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 7.2 through 8.4 do not properly perform proxy authentication during attemp…
Adaptive Security Appliance Software
Mitigation only
MEDIUM 6.5
CVE-2012-2414
main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk B…
Open Source
Patch available
HIGH 10.0
CVE-2012-1799EPSS 5%
The web server on the Siemens Scalance S Security Module firewall S602 V2, S612 V2, and S613 V2 with firmware before 2.3.0.3 does not limit the rate …
Scalance S Firmware
after 2.3.0
HIGH 7.5
CVE-2012-1806
The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password …
H0 Ecom
Mitigation only
HIGH 10.0
CVE-2012-1808
The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not r…
H0 Ecom
Mitigation only
HIGH 7.5
CVE-2012-1840
AjaXplorer 3.2.x before 3.2.5 and 4.0.x before 4.0.4 does not properly perform cookie authentication, which allows remote attackers to obtain login a…
Ajaxplorer
Patch available
MEDIUM 5.0
CVE-2012-1838
The web management interface on the LG-Nortel ELO GS24M switch allows remote attackers to bypass authentication, and consequently obtain cleartext cr…
Elo Gs24m Switch
Mitigation only
HIGH 7.9
CVE-2012-0400
EMC RSA enVision 4.x before 4.1 Patch 4 does not properly restrict the number of failed authentication attempts, which makes it easier for remote att…
Envision
Mitigation only
MEDIUM 5.0
CVE-2012-1256
The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account p…
Easyvista
after 2010
MEDIUM 5.0
CVE-2012-0239
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an admin…
Advantech Webaccess
after 6.0
HIGH 10.0
CVE-2012-0240
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbit…
Advantech Webaccess
after 6.0
HIGH 9.3
CVE-2011-4508
The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, C…
Wincc Flexible
Mitigation only
HIGH 10.0
CVE-2011-4514
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels…
Wincc Flexible
Mitigation only
HIGH 7.2
CVE-2011-3463
WebDAV Sharing in Apple Mac OS X 10.7.x before 10.7.3 does not properly perform authentication, which allows local users to gain privileges by levera…
Mac Os X
Mitigation only
CRITICAL 9.8
CVE-2012-0931
Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a d…
Modicon Quantum Plc
Mitigation only
HIGH 10.0
CVE-2011-3478EPSS 39%
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 1…
Pcanywhere
Mitigation only
MEDIUM 6.9
CVE-2011-5054
kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any confi…
Kcheckpass
Mitigation only
MEDIUM 5.8
CVE-2011-5053
The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed …
Wifi Protected Setup Protocol
Mitigation only
HIGH 9.3
CVE-2011-4644EPSS 8%
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally doe…
Splunk
after 4.2.5
MEDIUM 6.8
CVE-2011-3667
The User.offer_account_by_email WebService method in Bugzilla 2.x and 3.x before 3.4.13, 3.5.x and 3.6.x before 3.6.7, 3.7.x and 4.0.x before 4.0.3, …
Bugzilla
Mitigation only
HIGH 7.5
CVE-2011-3372
imap/nntpd.c in the NNTP server (nntpd) for Cyrus IMAPd 2.4.x before 2.4.12 allows remote attackers to bypass authentication by sending an AUTHINFO U…
Imapd
after 2.4.11
HIGH 10.0
CVE-2011-4860
The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates th…
Quantum Ethernet Module 140noe77100
after 5.0
HIGH 7.5
CVE-2011-4677
One Click Orgs before 1.2.3 does not have an off autocomplete attribute for authentication fields, which makes it easier for remote attackers to obta…
One Click Orgs
after 1.2.2