Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2007-4693
The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen …
Mac Os X
Patch available
MEDIUM 6.8
CVE-2007-5987
details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a di…
Bti Tracker
after 1.4.4
HIGH 7.5
CVE-2007-5988
blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary user…
Bti Tracker
after 1.4.4
MEDIUM 5.0
CVE-2007-5770
The (1) Net::ftptls, (2) Net::telnets, (3) Net::imap, (4) Net::pop, and (5) Net::smtp libraries in Ruby 1.8.5 and 1.8.6 do not verify that the common…
Ruby
Patch available
MEDIUM 6.8
CVE-2007-5913EPSS 7%
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attackers to (1) delete auth.inc.ph…
Jbc Explorer
after 7.20_rc1
HIGH 7.5
CVE-2007-5797
SQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…
Geronimo
Mitigation only
HIGH 10.0
CVE-2007-5791
The Vonage Motorola Phone Adapter VT 2142-VD does not properly verify that a SIP INVITE message originated from a legitimate server, which allows rem…
Motorola Phone Adapter Vt2142 Vd
Mitigation only
HIGH 7.5
CVE-2007-5752
adduser.php in PHP-AGTC Membership (AGTC-Membership) System 1.1a does not require authentication, which allows remote attackers to create accounts vi…
Php Agtc Membership System
Mitigation only
MEDIUM 6.8
CVE-2007-5714
The Gentoo ebuild of MLDonkey before 2.9.0-r3 has a p2p user account with an empty default password and valid login shell, which might allow remote a…
Mldonkey Ebuild
after 2.9.0
HIGH 7.5
CVE-2007-5578
Basic Analysis and Security Engine (BASE) before 1.3.8 sends a redirect to the web browser but does not exit, which allows remote attackers to bypass…
Basic Analysis And Security Engine
Patch available
HIGH 10.0
CVE-2007-5391
Unspecified vulnerability in HP Select Identity 4.01 through 4.01.010 and 4.10 through 4.13.001 allows remote attackers to obtain unspecified access …
Select Identity
No fix yet
HIGH 10.0
CVE-2007-5383
The Thomson/Alcatel SpeedTouch 7G router, as used for the BT Home Hub 6.2.6.B and earlier, allows remote attackers on an intranet to bypass authentic…
Speedtouch 7g Router
after 6.2.6.b
MEDIUM 6.5
CVE-2007-5374
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, which allows remote authenticat…
Lightblog
No fix yet
HIGH 10.0
CVE-2007-5006EPSS 21%
Multiple command handlers in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 do not verify if a peer…
Brightstor Arcserve Backup Laptops Desktops
Patch available
HIGH 7.5
CVE-2007-5152
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a cont…
Java System Access Manager
Mitigation only
MEDIUM 5.0
CVE-2007-5113
report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified …
Urchin
after 5.7.03
MEDIUM 5.0
CVE-2007-5085
Unspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…
Geronimo
Mitigation only
HIGH 10.0
CVE-2007-5057
NetSupport Manager Client before 10.20.0004 allows remote attackers to bypass the (1) basic and (2) authentication schemes by spoofing the NetSupport…
Netsupport Manager Client
Mitigation only
HIGH 9.0
CVE-2007-5008
The logins command in HP-UX B.11.31, B.11.23, and B.11.11 does not correctly report password status, which allows remote attackers to obtain privileg…
Hp Ux
Mitigation only
HIGH 10.0
CVE-2007-4747
The telnet service in Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/I…
Video Surveillance Ip Gateway Encoder Decoder
after 1.23.7
HIGH 10.0
CVE-2007-4548
The login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…
Geronimo
Patch available
MEDIUM 6.8
CVE-2007-4438
Session fixation vulnerability in Ampache before 3.3.3.5 allows remote attackers to hijack web sessions via unspecified vectors.
Ampache
after 3.3.3.4
HIGH 9.3
CVE-2007-4419
Admin.php in Olate Download (od) 3.4.1 uses an MD5 hash of the admin username, user id, and group id, to compose the OD3_AutoLogin authentication coo…
Olatedownload
No fix yet
HIGH 8.5
CVE-2007-4364
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to…
Commons
after 2.2
HIGH 9.3
CVE-2007-4203
Session fixation vulnerability in Mambo 4.6.2 CMS allows remote attackers to hijack web sessions by setting the Cookie parameter.
Mambo Open Source
Mitigation only
CRITICAL 9.8
CVE-2007-4043
file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a nam…
Securityreporter
after 4.6.3
MEDIUM 6.8
CVE-2007-3988
Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting…
Virtual Hosting Control System
after 2.4.7.1
HIGH 8.5
CVE-2007-3597
Session fixation vulnerability in Zen Cart 1.3.7 and earlier allows remote attackers to hijack web sessions by setting the Cookie parameter.
Zen Cart
after 1.3.7
HIGH 7.2
CVE-2007-3184
Cisco Trust Agent (CTA) before 2.1.104.0, when running on MacOS X, allows attackers with physical access to bypass authentication and modify System P…
Mac Os X
Patch available
MEDIUM 5.0
CVE-2007-3177
Ingate Firewall and SIParator before 4.5.2 allow remote attackers to bypass SIP authentication via a certain maddr parameter.
Ingate Firewall
after 4.5.1