Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 10.0 CVE-2011-1519EPSS 9% The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname speci… Lotus Domino Mitigation only Fix from $1,9502011-03-25 MEDIUM 6.8 CVE-2011-1025 bind.cpp in back-ndb in OpenLDAP 2.4.x before 2.4.24 does not require authentication for the root Distinguished Name (DN), which allows remote attack… Openldap Patch available Fix from $1,6002011-03-20 MEDIUM 6.8 CVE-2011-0438 nslcd/pam.c in the nss-pam-ldapd 0.8.0 PAM module returns a success code when a user is not found in LDAP, which allows remote attackers to bypass au… Nss Pam Ldapd Patch available Fix from $1,6002011-03-15 MEDIUM 5.0 CVE-2011-0435 Domain Technologie Control (DTC) before 0.32.9 does not require authentication for (1) admin/bw_per_month.php and (2) client/bw_per_month.php, which … Domain Technologie Control after 0.32.8 Fix from $1,6002011-03-07 MEDIUM 5.8 CVE-2011-0718 Red Hat Network (RHN) Satellite Server 5.4 does not use a time delay after a failed login attempt, which makes it easier for remote attackers to cond… Network Satellite Server Mitigation only Fix from $1,6002011-02-25 HIGH 7.5 CVE-2011-0392 Cisco TelePresence Recording Server devices with software 1.6.x do not require authentication for an XML-RPC interface, which allows remote attackers… Telepresence Recording Server Software Mitigation only Fix from $1,9502011-02-25 HIGH 7.5 CVE-2011-0380 Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to bypass authentication and invoke arbitrary methods via a malformed SOAP req… Telepresence Manager Mitigation only Fix from $1,9502011-02-25 HIGH 10.0 CVE-2011-0383EPSS 6% The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (… Telepresence Recording Server Software Mitigation only Fix from $1,9502011-02-25 HIGH 10.0 CVE-2011-0384EPSS 6% The Java Servlet framework on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require admin… Telepresence Multipoint Switch Software Mitigation only Fix from $1,9502011-02-25 MEDIUM 5.0 CVE-2011-0453 F-Secure Internet Gatekeeper for Linux 3.x before 3.03 does not require authentication for reading access logs, which allows remote attackers to obta… Internet Gatekeeper Patch available Fix from $1,6002011-02-18 HIGH 7.2 CVE-2011-0039 The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly process authenticati… Windows 2003 Server Mitigation only Fix from $1,9502011-02-09 HIGH 9.3 CVE-2011-0920EPSS 10% The Remote Console in IBM Lotus Domino, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to by… Lotus Domino Mitigation only Fix from $1,9502011-02-08 HIGH 9.3 CVE-2011-0688 Intel Alert Management System (aka AMS or AMS2), as used in Symantec Antivirus Corporate Edition (SAVCE) 10.x before 10.1 MR10, Symantec System Cente… Antivirus Mitigation only Fix from $1,9502011-01-31 HIGH 7.5 CVE-2011-0489EPSS 13% The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data,… Objectivity\/db No fix yet Fix from $1,9502011-01-18 MEDIUM 5.0 CVE-2010-4690 The Mobile User Security (MUS) service on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) does not properly … Adaptive Security Appliance Software after 8.3 Fix from $1,6002011-01-07 HIGH 9.3 CVE-2010-4573 The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows … Esxi Mitigation only Fix from $1,9502010-12-22 HIGH 7.5 CVE-2010-3905 The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attacke… Eucalyptus Mitigation only Fix from $1,9502010-12-22 HIGH 7.5 CVE-2010-4332EPSS 7% Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values… Pointter Php Content Management System No fix yet Fix from $1,9502010-12-22 HIGH 7.5 CVE-2010-4333EPSS 7% Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary va… Pointter Php Micro Blogging Social Network No fix yet Fix from $1,9502010-12-22 MEDIUM 5.0 CVE-2010-4481 phpMyAdmin before 3.4.0-beta1 allows remote attackers to bypass authentication and obtain sensitive information via a direct request to phpinfo.php, … phpMyAdmin after 3.3.9.0 Fix from $1,6002010-12-17 MEDIUM 5.0 CVE-2010-4488 Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (appl… Chrome after 8.0.552.214 Fix from $1,6002010-12-07 CRITICAL 9.8 CVE-2010-4478 OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attacke… Openssh after 5.6 Fix from $2,3002010-12-06 HIGH 10.0 CVE-2010-4279EPSS 66% The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypa… Pandora Fms after 3.1 Fix from $1,9502010-12-02 MEDIUM 5.8 CVE-2010-3868 Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, w… Certificate System Patch available Fix from $1,6002010-11-17 HIGH 10.0 CVE-2010-4232 The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 all… Cmnc 200 Firmware No fix yet Fix from $1,9502010-11-17 HIGH 7.5 CVE-2010-3896 The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers … Omnifind No fix yet Fix from $1,9502010-11-12 MEDIUM 6.4 CVE-2010-3852 The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easie… Luci after 0.22.4 Fix from $1,6002010-11-06 HIGH 7.5 CVE-2010-4121 The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows… Tivoli Provisioning Manager Os Deployment Mitigation only Fix from $1,9502010-10-28 HIGH 7.5 CVE-2008-7263 ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attacke… Pyftpdlib after 0.4.0 Fix from $1,9502010-10-19 HIGH 7.5 CVE-2007-6737 FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which mak… Pyftpdlib after 0.1.1 Fix from $1,9502010-10-19