Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 10.0 CVE-2009-0138 servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify t… Mac Os X Patch available Fix from $1,9502009-02-13 HIGH 7.5 CVE-2008-6118 win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access by setting the loggedin cook… Goople Cms No fix yet Fix from $1,9502009-02-11 HIGH 7.5 CVE-2009-0460 Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in the adminid cook… Ware Support No fix yet Fix from $1,9502009-02-10 HIGH 7.5 CVE-2009-0461 Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative access via an integer value in th… Password Protect No fix yet Fix from $1,9502009-02-10 HIGH 10.0 CVE-2009-0492 Unspecified vulnerability in SimpleIrcBot before 1.0 Stable has unknown impact and attack vectors related to an "auth vulnerability." Simpleircbot Patch available Fix from $1,9502009-02-10 HIGH 7.5 CVE-2008-6092 phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an admin=ja cookie. Ranking Script No fix yet Fix from $1,9502009-02-09 MEDIUM 5.0 CVE-2002-2427 The security handler in GoAhead WebServer before 2.1.1 allows remote attackers to bypass authentication and obtain access to protected web content vi… Goahead Webserver after 2.1 Fix from $1,6002009-02-06 HIGH 7.5 CVE-2009-0412 The ProcessLogin function in class.auth.php in Interspire Shopping Cart (ISC) 4.0.1 Ultimate edition allows remote attackers to bypass authentication… Shopping Cart Mitigation only Fix from $1,9502009-02-03 MEDIUM 6.8 CVE-2008-6039 Session fixation vulnerability in BLUEPAGE CMS 2.5 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Bluepage Cms 2.5.8+ Fix from $1,6002009-02-03 MEDIUM 6.8 CVE-2008-6045 Session fixation vulnerability in shopping_cart.php in xt:Commerce 3.0.4 and earlier allows remote attackers to hijack web sessions by setting the XT… Xt Commerce after 3.0.4 Fix from $1,6002009-02-03 MEDIUM 6.0 CVE-2008-5082 The verifyProof function in the Token Processing System (TPS) component in Red Hat Certificate System (RHCS) 7.1 through 7.3 and Dogtag Certificate S… Dogtag Certificate System Mitigation only Fix from $1,6002009-01-30 HIGH 7.5 CVE-2008-6009 SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. Sg Real Estate Portal No fix yet Fix from $1,9502009-01-30 HIGH 7.5 CVE-2009-0280 Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the crypt cookie to 1. Asp Project No fix yet Fix from $1,9502009-01-27 HIGH 7.5 CVE-2008-5967 admin/index.php in PHP iCalendar 2.3.4, 2.24, and earlier does not require administrative authentication for an addupdate action, which allows remote… Phpicalendar after 2.3.4 Fix from $1,9502009-01-26 MEDIUM 6.8 CVE-2008-5964 Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID paramete… Impresscms after 1.0.3 Fix from $1,6002009-01-23 HIGH 7.5 CVE-2009-0256 Session fixation vulnerability in the authentication library in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote… TYPO3 Mitigation only Fix from $1,9502009-01-22 HIGH 7.5 CVE-2008-5945 Nukeviet 2.0 Beta allows remote attackers to bypass authentication and gain administrative access by setting the admf cookie to 1. NOTE: the provena… Nukeviet No fix yet Fix from $1,9502009-01-22 MEDIUM 6.5 CVE-2009-0030 A certain Red Hat patch for SquirrelMail 1.4.8 sets the same SQMSESSID cookie value for all sessions, which allows remote authenticated users to acce… Squirrelmail Mitigation only Fix from $1,6002009-01-21 MEDIUM 5.0 CVE-2009-0124 The tqsl_verifyDataBlock function in openssl_cert.cpp in American Radio Relay League (ARRL) tqsllib 2.0 does not properly check the return value from… Tqsllib No fix yet Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2009-0125 NOTE: this issue has been disputed by the upstream vendor. nasl/nasl_crypto2.c in the Nessus Attack Scripting Language library (aka libnasl) 2.2.11 d… Libnasl No fix yet Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2009-0126 The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not ch… Boinc Client No fix yet Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2009-0127 M2Crypto does not properly check the return value from the OpenSSL EVP_VerifyFinal, DSA_verify, ECDSA_verify, DSA_do_verify, and ECDSA_do_verify func… M2crypto No fix yet Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2009-0128 plugins/crypto/openssl/crypto_openssl.c in Simple Linux Utility for Resource Management (aka SLURM or slurm-llnl) does not properly check the return … Slurm No fix yet Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2009-0129 libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote … Libcrypt Openssl Dsa Perl No fix yet Fix from $1,6002009-01-15 HIGH 7.5 CVE-2009-0130 lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow remote at… Erlang No fix yet Fix from $1,9502009-01-15 HIGH 7.5 CVE-2008-5880 admin/auth.php in Gobbl CMS 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the auth cookie to "ok". Gobbl Cms No fix yet Fix from $1,9502009-01-08 MEDIUM 5.0 CVE-2009-0048 OpenEvidence 1.0.6 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to b… Openevidence after 1.0.6 Fix from $1,6002009-01-07 MEDIUM 5.0 CVE-2009-0049 Belgian eID middleware (eidlib) 2.6.0 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows re… Eidlib after 2.6.0 Fix from $1,6002009-01-07 MEDIUM 5.0 CVE-2009-0051 ZXID 0.29 and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validati… Zxid after 0.29 Fix from $1,6002009-01-07 MEDIUM 5.0 CVE-2009-0047 Gale 0.99 and earlier does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass val… Gale after 0.99 Fix from $1,6002009-01-07