Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
CRITICAL 9.8 CVE-2009-2422 The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_reques… Ruby On Rails 2.3.3 / 10.6.3+ Fix from $2,3002009-07-10 CRITICAL 9.8 CVE-2009-2382EPSS 6% admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access by setting the PHPMYBCAdmin c… Phpmyblockchecker No fix yet Fix from $2,3002009-07-08 HIGH 7.5 CVE-2009-2328 admin/edit_user.php in KerviNet Forum 1.1 and earlier does not require administrative authentication, which allows remote attackers to delete arbitra… Kervinet Forum after 1.1 Fix from $1,9502009-07-05 HIGH 7.8 CVE-2009-2257EPSS 7% The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to… Dg632 No fix yet Fix from $1,9502009-06-30 MEDIUM 6.8 CVE-2009-2255EPSS 31% Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/record_company.php, which allows remote attackers to exe… Zen Cart after 1.3.8a Fix from $1,6002009-06-30 HIGH 7.5 CVE-2009-2233 The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain administrative access by set… Gallery Search Engine No fix yet Fix from $1,9502009-06-26 HIGH 7.5 CVE-2009-2231 MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie. Midas No fix yet Fix from $1,9502009-06-26 CRITICAL 9.8 CVE-2009-2168EPSS 12% cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials ar… 7ammel after 1.0.1 Fix from $2,3002009-06-22 MEDIUM 6.4 CVE-2009-2159 backup-database.php in TorrentTrader Classic 1.09 does not require administrative authentication, which allows remote attackers to create and downloa… Torrenttrader Classic No fix yet Fix from $1,6002009-06-22 HIGH 7.5 CVE-2009-2117 uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the kulladi cookie to a v… Phportal No fix yet Fix from $1,9502009-06-18 MEDIUM 6.8 CVE-2009-1390 Mutt 1.5.19, when linked against (1) OpenSSL (mutt_ssl.c) or (2) GnuTLS (mutt_ssl_gnutls.c), allows connections when only one TLS certificate in the … Mutt Patch available Fix from $1,6002009-06-16 MEDIUM 6.8 CVE-2009-2058 Apple Safari before 3.2.2 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a p… Safari after 3.2.2 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2059 Opera, possibly before 9.25, uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from … Opera Browser after 9.22 Fix from $1,6002009-06-15 MEDIUM 5.8 CVE-2009-2060 src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided… Chrome after 1.0.154.52 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2062 Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execut… Safari after 3.2.1 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2063 Opera, possibly before 9.25, processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to exe… Opera Browser after 9.24 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2064 Microsoft Internet Explorer 8, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which a… Internet Explorer after 8 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2065 Mozilla Firefox 3.0.10, and possibly other versions, detects http content in https web pages only when the top-level frame uses https, which allows m… Firefox after 3.0.9 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2066 Apple Safari detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute ar… Safari after 3.2.1 Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2067 Opera detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute arbitrary… Opera Browser after 9.22 Fix from $1,6002009-06-15 MEDIUM 5.8 CVE-2009-2068 Google Chrome detects http content in https web pages only when the top-level frame uses https, which allows man-in-the-middle attackers to execute a… Opera Mitigation only Fix from $1,6002009-06-15 MEDIUM 5.8 CVE-2009-2069 Microsoft Internet Explorer before 8 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which a… Ie Mitigation only Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2070 Opera displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows man-in-the-middle attacke… Opera Browser Mitigation only Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-2071 Google Chrome before 1.0.154.53 displays a cached certificate for a (1) 4xx or (2) 5xx CONNECT response page returned by a proxy server, which allows… Chrome after 1.0.154.52 Fix from $1,6002009-06-15 MEDIUM 5.4 CVE-2009-2072 Apple Safari does not require a cached certificate before displaying a lock icon for an https web site, which allows man-in-the-middle attackers to s… Safari after 3.2.1 Fix from $1,6002009-06-15 MEDIUM 5.8 CVE-2009-2057 Microsoft Internet Explorer before 8 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT respon… Ie No fix yet Fix from $1,6002009-06-15 MEDIUM 6.8 CVE-2009-1836 Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a docume… Firefox after 3.0.10 Fix from $1,6002009-06-12 HIGH 7.5 CVE-2009-2040 admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authentication and create administrative … Grestul No fix yet Fix from $1,9502009-06-12 HIGH 7.5 CVE-2009-1122EPSS 98% The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote atta… Internet Information Services Patch available Fix from $1,9502009-06-10 HIGH 7.5 CVE-2009-1535EPSS 98% The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, … Internet Information Services Patch available Fix from $1,9502009-06-10