Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.4 CVE-2010-3739 The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and… Db2 Universal Database after 9.5 Fix from $1,6002010-10-05 MEDIUM 5.0 CVE-2010-3685 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking fo… Drupal Patch available Fix from $1,6002010-09-29 MEDIUM 5.0 CVE-2010-3686 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring th… Drupal Patch available Fix from $1,6002010-09-29 MEDIUM 5.0 CVE-2010-3091 The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying t… Drupal Patch available Fix from $1,6002010-09-29 MEDIUM 6.8 CVE-2010-1820 Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass t… Mac Os X Patch available Fix from $1,6002010-09-21 MEDIUM 6.8 CVE-2010-2731EPSS 31% Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enable… Mitigation only Fix from $1,6002010-09-15 MEDIUM 5.1 CVE-2010-2940 The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are… Sssd Mitigation only Fix from $1,6002010-08-30 MEDIUM 6.4 CVE-2010-1802 libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-… Libsecurity Patch available Fix from $1,6002010-08-25 HIGH 7.5 CVE-2009-4987EPSS 6% admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by settin… Free Image Hosting Script No fix yet Fix from $1,9502010-08-25 HIGH 7.5 CVE-2010-2944 The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, wh… Zope Ldapuserfolder Patch available Fix from $1,9502010-08-20 HIGH 9.3 CVE-2010-0834 The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 ne… Ubuntu Linux Patch available Fix from $1,9502010-08-10 MEDIUM 5.0 CVE-2010-2927 The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of ser… Tivoli Directory Server after 6.0.0.8 Fix from $1,6002010-08-02 HIGH 9.3 CVE-2010-0833 The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storag… Likewise Open Patch available Fix from $1,9502010-07-28 HIGH 7.5 CVE-2009-4927 WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cookie, as demonstrated by settin… Wbnews No fix yet Fix from $1,9502010-07-12 HIGH 7.5 CVE-2009-4929 admin/manage_users.php in TotalCalendar 2.4 does not require administrative authentication, which allows remote attackers to change arbitrary passwor… Totalcalender No fix yet Fix from $1,9502010-07-12 MEDIUM 6.4 CVE-2010-2668 Unspecified vulnerability in Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 allows remote attackers to bypass authentication and… Alpha Ethernet Adapter Ii Web Manager Mitigation only Fix from $1,6002010-07-08 HIGH 7.5 CVE-2010-1670 Mahara before 1.0.15, 1.1.x before 1.1.9, and 1.2.x before 1.2.5 has improper configuration options for authentication plugins associated with logins… Mahara after 1.0.14 Fix from $1,9502010-07-06 HIGH 9.3 CVE-2010-2620EPSS 30% Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or othe… Open Ftpd after 1.2 Fix from $1,9502010-07-02 MEDIUM 6.8 CVE-2009-4909 admin/index.php in oBlog allows remote attackers to conduct brute-force password guessing attacks via HTTP requests. Oblog No fix yet Fix from $1,6002010-06-25 HIGH 9.3 CVE-2008-4389 Symantec AppStream 5.2.x and Symantec Workspace Streaming (SWS) 6.1.x before 6.1 SP4 do not properly perform authentication, which allows remote Work… Workspace Streaming Mitigation only Fix from $1,9502010-06-17 HIGH 7.2 CVE-2010-1375 NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to … Mac Os X Patch available Fix from $1,9502010-06-17 MEDIUM 6.4 CVE-2010-2026 The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass aut… Scientific Atlanta Webstar Dpc2100r2 No fix yet Fix from $1,6002010-05-26 MEDIUM 6.8 CVE-2010-1454 com.springsource.tcserver.serviceability.rmi.JmxSocketListener in VMware SpringSource tc Server Runtime 6.0.19 and 6.0.20 before 6.0.20.D, and 6.0.25… Tc Server Mitigation only Fix from $1,6002010-05-19 MEDIUM 5.1 CVE-2010-1910 The Forgot Password implementation in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to reset passwords of… Consona Dynamic Agent Patch available Fix from $1,6002010-05-12 HIGH 7.5 CVE-2009-4843 ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attacker… Virtualiq No fix yet Fix from $1,9502010-05-07 MEDIUM 6.8 CVE-2010-1613 Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the "Regenerate session id during login" setting by default, which makes it easier for remote att… Moodle Mitigation only Fix from $1,6002010-04-29 MEDIUM 6.8 CVE-2010-1596 Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an em… Support Incident Tracker after 3.50 Fix from $1,6002010-04-28 HIGH 7.5 CVE-2009-4830 Unspecified vulnerability in OpenX 2.8.1 and 2.8.2 allows remote attackers to bypass authentication and obtain access to an Administrator account via… Openx Patch available Fix from $1,9502010-04-27 MEDIUM 5.0 CVE-2009-4821 The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the… Dir 615 No fix yet Fix from $1,6002010-04-27 HIGH 7.5 CVE-2009-4808 admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_adm… Php Article Publisher No fix yet Fix from $1,9502010-04-23