Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.4 CVE-2008-6707 The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform aut… Sip Enablement Services Mitigation only Fix from $1,6002009-04-10 HIGH 7.5 CVE-2008-6714EPSS 12% admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by setting the xecms_username co… Xecms No fix yet Fix from $1,9502009-04-10 HIGH 7.8 CVE-2009-1155 Cisco Adaptive Security Appliances (ASA) 5500 Series and PIX Security Appliances 7.1(1) through 7.1(2)82, 7.2 before 7.2(4)27, 8.0 before 8.0(4)25, a… Adaptive Security Appliance 5500 Patch available Fix from $1,9502009-04-09 HIGH 7.5 CVE-2008-6664 action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the shuser and shpass cookies… Sh News No fix yet Fix from $1,9502009-04-08 HIGH 7.5 CVE-2008-6667 A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator privileges by setting the mobsuse… A\+ Php Scripts News Management System No fix yet Fix from $1,9502009-04-08 HIGH 7.5 CVE-2008-6581 login.php in PhpAddEdit 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the addedit cookie parameter. Phpaddedit Patch available Fix from $1,9502009-04-02 MEDIUM 6.8 CVE-2008-6569 Session fixation vulnerability in Cybozu Garoon 2.0.0 through 2.1.3 allows remote attackers to hijack web sessions via the session ID in the login pa… Garoon Mitigation only Fix from $1,6002009-03-31 MEDIUM 5.5 CVE-2009-0892 The administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3 allows attackers to hijack user sessi… Websphere Application Server Patch available Fix from $1,6002009-03-31 HIGH 7.5 CVE-2008-6553 microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an administrator, which allows … Micro Cms after 0.3.5 Fix from $1,9502009-03-30 HIGH 7.5 CVE-2008-6523 auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by setting the oiauth cookie. NOT… Openinvoice No fix yet Fix from $1,9502009-03-25 MEDIUM 5.5 CVE-2009-0891 The Web Services Security component in IBM WebSphere Application Server 7.0 before Fix Pack 1 (7.0.0.1), 6.1 before Fix Pack 23 (6.1.0.23),and 6.0.2 … Websphere Application Server Patch available Fix from $1,6002009-03-25 HIGH 7.5 CVE-2009-1050 Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYourself cookie. Bloginator No fix yet Fix from $1,9502009-03-24 MEDIUM 6.8 CVE-2008-6455 Session fixation vulnerability in Edikon phpShop 0.8.1 allows remote attackers to hijack web sessions via unspecified vectors. NOTE: the provenance … Phpshop No fix yet Fix from $1,6002009-03-13 HIGH 7.5 CVE-2009-0864 S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for the login cookie. S Cms No fix yet Fix from $1,9502009-03-10 MEDIUM 6.8 CVE-2009-0853 login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obtain administrative access via … Celerbb No fix yet Fix from $1,6002009-03-09 HIGH 7.5 CVE-2008-6445 Unspecified vulnerability in YourPlace before 1.0.1 has unknown impact and attack vectors, possibly related to improper authentication and the abilit… Yourplace after 1.0 Fix from $1,9502009-03-09 MEDIUM 5.0 CVE-2008-6440 Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't… Cerberus Helpdesk after 3.3 Fix from $1,6002009-03-06 HIGH 7.5 CVE-2008-6411 Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting the login cookie to 1. Explay Cms after 2.1 Fix from $1,9502009-03-06 HIGH 7.5 CVE-2008-6307 E-topbiz Link Back Checker 1 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "admin." Link Back Checker No fix yet Fix from $1,9502009-02-26 HIGH 9.0 CVE-2009-0614 Unspecified vulnerability in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) … Unified Meetingplace Web Conferencing 6.0 / 7.0+ Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6300 Galatolo WebManager 1.3a allows remote attackers to bypass authentication and gain administrative access by setting the (1) gwm_user and (2) gwm_pass… Galatolo Webmanager No fix yet Fix from $1,9502009-02-26 HIGH 7.5 CVE-2008-6269 Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the administrator, by setting the (1) se… Joovili No fix yet Fix from $1,9502009-02-25 MEDIUM 6.5 CVE-2009-0440 IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authe… Websphere Partner Gateway Patch available Fix from $1,6002009-02-22 MEDIUM 6.9 CVE-2009-0655 Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user. Veriface No fix yet Fix from $1,6002009-02-20 MEDIUM 6.8 CVE-2009-0642 ext/openssl/ossl_ocsp.c in Ruby 1.8 and 1.9 does not properly check the return value from the OCSP_basic_verify function, which might allow remote at… Ruby No fix yet Fix from $1,6002009-02-20 HIGH 7.5 CVE-2008-6162 Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cookie to 1 and the usNic… Bux.to Clone Script No fix yet Fix from $1,9502009-02-20 HIGH 7.5 CVE-2008-6143EPSS 6% OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account name in the username cookie. Owenpoll No fix yet Fix from $1,9502009-02-16 MEDIUM 6.8 CVE-2008-6128 Session fixation vulnerability in moziloCMS 1.10.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Mozilocms after 1.10.2 Fix from $1,6002009-02-13 MEDIUM 6.0 CVE-2008-6131 Session fixation vulnerability in moziloWiki 1.0.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Mozilowiki after 1.0.1 Fix from $1,6002009-02-13 MEDIUM 6.2 CVE-2009-0360 Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows… Pam Krb5 after 3.12 Fix from $1,6002009-02-13