Vulnerability index

Browse CVEs

4,343 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
HIGH 7.5 CVE-2008-2347 MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admi… Mypicgallery No fix yet Fix from $1,9502008-05-20 HIGH 7.5 CVE-2008-2282 admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_adm… Internet Photoshow No fix yet Fix from $1,9502008-05-18 HIGH 7.5 CVE-2008-2298 Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. Web Slider No fix yet Fix from $1,9502008-05-18 HIGH 7.5 CVE-2008-2269 AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin coo… Austinsmoke Gastracker No fix yet Fix from $1,9502008-05-16 HIGH 7.5 CVE-2008-1930EPSS 5% The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote … WordPress Patch available Fix from $1,9502008-04-28 HIGH 7.5 CVE-2008-1971 phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) … Phshoutbox Final after 1.5 Fix from $1,9502008-04-27 MEDIUM 6.4 CVE-2008-1938 Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain se… Mylo Com 2 after 1.100 Fix from $1,6002008-04-25 HIGH 7.5 CVE-2008-1904 Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attacke… Ccmail after 1.0.1 Fix from $1,9502008-04-22 MEDIUM 6.8 CVE-2008-1883 The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attack… Blackboard Academic Suite after 7 Fix from $1,6002008-04-18 MEDIUM 6.8 CVE-2007-6714 DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypas… Dbmail Patch available Fix from $1,6002008-04-17 HIGH 7.5 CVE-2008-1868 admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b… Pixel Motion Blog No fix yet Fix from $1,9502008-04-17 HIGH 7.5 CVE-2008-1727EPSS 7% KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin acco… Knowledgequest No fix yet Fix from $1,9502008-04-11 HIGH 10.0 CVE-2008-1154EPSS 5% The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and… Emergency Responder Patch available Fix from $1,9502008-04-04 HIGH 7.5 CVE-2008-0555 The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (… Apache Ssl Patch available Fix from $1,9502008-04-04 HIGH 7.2 CVE-2008-0706 Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged acces… Presario A900 Patch available Fix from $1,9502008-03-31 HIGH 7.5 CVE-2008-0926EPSS 58% The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which … Edirectory after 8.7.3.10 Fix from $1,9502008-03-28 MEDIUM 5.0 CVE-2008-1238 Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba… Firefox after 2.0.0.12 Fix from $1,6002008-03-27 MEDIUM 6.4 CVE-2008-1469 Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote… Gallarific Mitigation only Fix from $1,6002008-03-24 HIGH 7.5 CVE-2008-1395 Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex… Plone Cms Mitigation only Fix from $1,9502008-03-20 MEDIUM 6.3 CVE-2008-1356 Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local us… Solaris Patch available Fix from $1,6002008-03-17 HIGH 7.5 CVE-2008-1334 cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP t… Home Hub No fix yet Fix from $1,9502008-03-13 MEDIUM 5.0 CVE-2008-1321EPSS 8% The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of … Asg Sentry after 7.0.0 Fix from $1,6002008-03-13 HIGH 7.5 CVE-2008-1327 Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct requ… Gallarific No fix yet Fix from $1,9502008-03-13 HIGH 10.0 CVE-2008-1244 cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform … F5d7230 4 No fix yet Fix from $1,9502008-03-10 HIGH 9.3 CVE-2008-1259 The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authent… P 2602hw D1a No fix yet Fix from $1,9502008-03-10 HIGH 10.0 CVE-2008-1262EPSS 9% The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remot… Wimax Prost No fix yet Fix from $1,9502008-03-10 HIGH 7.5 CVE-2008-1264 The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil… Wrt54g Mitigation only Fix from $1,9502008-03-10 HIGH 10.0 CVE-2008-1268 The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab… Wrt54g Mitigation only Fix from $1,9502008-03-10 HIGH 7.1 CVE-2008-1269 cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attac… Gate2 Plus Wi Fi No fix yet Fix from $1,9502008-03-10 MEDIUM 6.4 CVE-2008-1134 OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attacke… Interneserviceslosungen Mitigation only Fix from $1,6002008-03-04