Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.5
CVE-2008-3425
Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenti…
Java System Web Server Plugin
Mitigation only
MEDIUM 6.5
CVE-2008-3428
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to mat…
Phpfreechat
Patch available
HIGH 10.0
CVE-2008-3411
The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/conf…
Akw D800
Mitigation only
MEDIUM 5.0
CVE-2008-3407
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.
Phplinkat
No fix yet
HIGH 7.5
CVE-2008-3375
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrati…
Jamroom
after 3.3.8
HIGH 7.5
CVE-2008-3317EPSS 8%
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…
Maian Search
after 1.1
HIGH 7.5
CVE-2008-3318EPSS 8%
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…
Weblog
after 4.0
HIGH 7.5
CVE-2008-3319EPSS 8%
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrar…
Links
after 3.1
HIGH 7.5
CVE-2008-3320EPSS 7%
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbi…
Guestbook
after 3.2
HIGH 7.5
CVE-2008-3321EPSS 8%
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbit…
Maian Uploader
after 4.0
HIGH 7.5
CVE-2008-3322EPSS 7%
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitra…
Recipe
after 1.2
HIGH 7.5
CVE-2008-3299EPSS 6%
eSyndiCat 1.6 allows remote attackers to bypass authentication and gain administrative access by setting the admin_lng cookie value to 1. NOTE: the p…
Esyndicat
No fix yet
MEDIUM 6.4
CVE-2008-3292EPSS 7%
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by setting the photoalbumadmin coo…
Ezwebalbum
No fix yet
HIGH 7.8
CVE-2008-3264
The FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B…
Asterisk Appliance Developer Kit
Mitigation only
HIGH 7.5
CVE-2008-3211
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cook…
Free Image Hosting Script
No fix yet
HIGH 7.5
CVE-2008-3203
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to add, edit, and delete web cont…
Auracms
No fix yet
HIGH 7.5
CVE-2008-2801
Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary…
Firefox
after 2.0.0.14
HIGH 9.3
CVE-2008-3033
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin f…
Rss Aggregator
Mitigation only
HIGH 7.5
CVE-2008-2920
admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to creat…
Eztechhelp Ezcms
after 1.2
MEDIUM 5.0
CVE-2008-2730
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) …
Unified Communications Manager
Patch available
MEDIUM 6.4
CVE-2008-2879
Benja CMS 0.1 does not require authentication for access to admin/, which allows remote attackers to add or delete a menu.
Benja Cms
No fix yet
HIGH 10.0
CVE-2008-2833
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload and execute arbitrary files in…
Le.cms
after 1.4
HIGH 9.3
CVE-2008-2705
Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Ente…
Java System Access Manager
No fix yet
HIGH 10.0
CVE-2008-0960EPSS 69%
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Se…
Session And Resource Control
Patch available
HIGH 7.1
CVE-2008-1106
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request…
Client
after 3322
HIGH 7.5
CVE-2008-2406
The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via …
Java Asp Server
after 4.0.2
MEDIUM 5.0
CVE-2008-2524
BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_user…
Blogphp
Mitigation only
HIGH 10.0
CVE-2008-2528
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to by…
Access Gateway
after 4.5.7
HIGH 7.8
CVE-2008-0536
Unspecified vulnerability in the SSH server in (1) Cisco Service Control Engine (SCE) 3.0.x before 3.0.7 and 3.1.x before 3.1.0, and (2) Icon Labs Ic…
Service Control Engine
after 3.1.6
HIGH 9.3
CVE-2008-1949EPSS 6%
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello m…
Gnutls
Patch available