Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2008-4752 TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login cookie to admin. Tlnews No fix yet Fix from $1,9502008-10-27 HIGH 9.0 CVE-2008-4722 Unspecified vulnerability in Sun Integrated Lights-Out Manager (ILOM) 2.0.1.5 through 2.0.4.26 allows remote authenticated users to (1) access the se… Integrated Lights Out Manager after 7.1.6 Fix from $1,9502008-10-23 HIGH 7.5 CVE-2008-4721 PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting the PostCommentsAdmin cookie … Post Comment No fix yet Fix from $1,9502008-10-23 HIGH 7.5 CVE-2008-4708 BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admin_session cookie to 1. Bbzl.php No fix yet Fix from $1,9502008-10-23 HIGH 7.5 CVE-2008-4714 Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers t… Atomic Photo Album No fix yet Fix from $1,9502008-10-23 HIGH 7.5 CVE-2008-4689 Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions. Mantis after 1.1.2 Fix from $1,9502008-10-22 MEDIUM 6.8 CVE-2008-4679 The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store C… Websphere Application Server Patch available Fix from $1,6002008-10-22 HIGH 7.5 CVE-2008-4649 Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. Elxis Cms No fix yet Fix from $1,9502008-10-22 HIGH 7.5 CVE-2008-4622 The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by … Phpfastnews No fix yet Fix from $1,9502008-10-21 HIGH 7.5 CVE-2008-4614 PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topi… Portalapp Patch available Fix from $1,9502008-10-20 HIGH 7.8 CVE-2008-4576 sctp in Linux kernel before 2.6.25.18 allows remote attackers to cause a denial of service (OOPS) via an INIT-ACK that states the peer does not suppo… Linux Kernel after 2.6.25.17 Fix from $1,9502008-10-15 HIGH 10.0 CVE-2008-3466EPSS 78% Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to … Host Integration Server 2000 Patch available Fix from $1,9502008-10-15 HIGH 7.5 CVE-2008-4515 Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authenti… K9 Web Protection Mitigation only Fix from $1,9502008-10-09 MEDIUM 5.8 CVE-2008-3814 Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication… Unity Patch available Fix from $1,6002008-10-08 HIGH 7.5 CVE-2008-4427 changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows re… Personal Information Manager after 1.0 Fix from $1,9502008-10-03 MEDIUM 6.4 CVE-2008-4319 fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrar… Php Filemanager after 1.18 Fix from $1,6002008-09-29 HIGH 7.5 CVE-2008-4244 Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1. Rianxosencabos Cms No fix yet Fix from $1,9502008-09-25 MEDIUM 5.0 CVE-2008-4146 Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-coun… Addalink after 1.0 Fix from $1,6002008-09-24 MEDIUM 6.4 CVE-2008-4167 useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add… Ezphotogallery No fix yet Fix from $1,6002008-09-22 HIGH 7.6 CVE-2008-3610 Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password a… Mac Os X Patch available Fix from $1,9502008-09-16 MEDIUM 6.3 CVE-2008-3611 Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, whic… Mac Os X Patch available Fix from $1,6002008-09-16 HIGH 7.5 CVE-2008-4081 admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie. Stash No fix yet Fix from $1,9502008-09-15 MEDIUM 5.8 CVE-2008-3905 resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and … Ruby after 1.9 Fix from $1,6002008-09-04 HIGH 7.5 CVE-2008-3891 The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors… Google Apps Mitigation only Fix from $1,9502008-09-03 CRITICAL 9.1 CVE-2008-3738 Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors. Lacoodast after 2.1.3 Fix from $2,3002008-08-27 HIGH 7.5 CVE-2008-3729 Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrati… Mailscan No fix yet Fix from $1,9502008-08-20 HIGH 10.0 CVE-2008-3703EPSS 12% The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0,… Veritas Storage Foundation Patch available Fix from $1,9502008-08-18 HIGH 7.8 CVE-2008-3579 Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sens… Atmail Mitigation only Fix from $1,9502008-08-10 MEDIUM 5.0 CVE-2008-3503 RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers… Plain Black Webgui Mitigation only Fix from $1,6002008-08-06 HIGH 7.5 CVE-2008-3504 Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies… Mask Php File Manager after 2.2 Fix from $1,9502008-08-06