Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2008-2347
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting the userID parameter to "admi…
Mypicgallery
No fix yet
HIGH 7.5
CVE-2008-2282
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_adm…
Internet Photoshow
No fix yet
HIGH 7.5
CVE-2008-2298
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.
Web Slider
No fix yet
HIGH 7.5
CVE-2008-2269
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin coo…
Austinsmoke Gastracker
No fix yet
HIGH 7.5
CVE-2008-1930EPSS 5%
The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote …
WordPress
Patch available
HIGH 7.5
CVE-2008-1971
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) …
Phshoutbox Final
after 1.5
MEDIUM 6.4
CVE-2008-1938
Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain se…
Mylo Com 2
after 1.100
HIGH 7.5
CVE-2008-1904
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session, which allows remote attacke…
Ccmail
after 1.0.1
MEDIUM 6.8
CVE-2008-1883
The server in Blackboard Academic Suite 7.x stores MD5 password hashes that are provided directly by clients, which makes it easier for remote attack…
Blackboard Academic Suite
after 7
MEDIUM 6.8
CVE-2007-6714
DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypas…
Dbmail
Patch available
HIGH 7.5
CVE-2008-1868
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database b…
Pixel Motion Blog
No fix yet
HIGH 7.5
CVE-2008-1727EPSS 7%
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers to create arbitrary admin acco…
Knowledgequest
No fix yet
HIGH 10.0
CVE-2008-1154EPSS 5%
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and…
Emergency Responder
Patch available
HIGH 7.5
CVE-2008-0555
The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (…
Apache Ssl
Patch available
HIGH 7.2
CVE-2008-0706
Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged acces…
Presario A900
Patch available
HIGH 7.5
CVE-2008-0926EPSS 58%
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which …
Edirectory
after 8.7.3.10
MEDIUM 5.0
CVE-2008-1238
Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Ba…
Firefox
after 2.0.0.12
MEDIUM 6.4
CVE-2008-1469
Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote…
Gallarific
Mitigation only
HIGH 7.5
CVE-2008-1395
Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for contex…
Plone Cms
Mitigation only
MEDIUM 6.3
CVE-2008-1356
Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local us…
Solaris
Patch available
HIGH 7.5
CVE-2008-1334
cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP t…
Home Hub
No fix yet
MEDIUM 5.0
CVE-2008-1321EPSS 8%
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of …
Asg Sentry
after 7.0.0
HIGH 7.5
CVE-2008-1327
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct requ…
Gallarific
No fix yet
HIGH 10.0
CVE-2008-1244
cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform …
F5d7230 4
No fix yet
HIGH 9.3
CVE-2008-1259
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authent…
P 2602hw D1a
No fix yet
HIGH 10.0
CVE-2008-1262EPSS 9%
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication credentials, which allows remot…
Wimax Prost
No fix yet
HIGH 7.5
CVE-2008-1264
The Linksys WRT54G router has "admin" as its default FTP password, which allows remote attackers to access sensitive files including nvram.cfg, a fil…
Wrt54g
Mitigation only
HIGH 10.0
CVE-2008-1268
The FTP server on the Linksys WRT54G 7 router with 7.00.1 firmware does not verify authentication credentials, which allows remote attackers to estab…
Wrt54g
Mitigation only
HIGH 7.1
CVE-2008-1269
cp06_wifi_m_nocifr.cgi in the admin panel on the Alice Gate 2 Plus Wi-Fi router does not verify authentication credentials, which allows remote attac…
Gate2 Plus Wi Fi
No fix yet
MEDIUM 6.4
CVE-2008-1134
OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attacke…
Interneserviceslosungen
Mitigation only