Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
Debian Linux MEDIUM 6.5
CVE-2023-52160

The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to…

Fix: after 2.10
Fix from $1,600 2024-02-22
Debian Linux HIGH 7.5
CVE-2021-36369

An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH …

Fix: after 2020.81
Fix from $1,950 2022-10-12
Debian Linux MEDIUM 6.5
CVE-2022-2553

The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes …

Fix: after 1.0
Fix from $1,600 2022-07-28
Debian Linux CRITICAL 9.8
CVE-2021-40874

An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (…

Patch available
Fix from $2,300 2022-07-18
Debian Linux HIGH 8.8
CVE-2022-30550

An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver …

Fix: 2.4.0+
Fix from $1,950 2022-07-17
Debian Linux HIGH 8.8
CVE-2022-1049

A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi…

Fix: after 0.11.2
Fix from $1,950 2022-03-25
Debian Linux CRITICAL 9.8
CVE-2022-0730

Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.

No fix yet
Fix from $2,300 2022-03-03
Debian Linux HIGH 7.2
CVE-2020-25719

A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b…

Patch available
Fix from $1,950 2022-02-18
Debian Linux MEDIUM 5.9
CVE-2016-2124

A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w…

Patch available
Fix from $1,600 2022-02-18
Debian Linux CRITICAL 9.1
CVE-2021-3850

Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.

Fix: after 5.20.21
Fix from $2,300 2022-01-25
Debian Linux MEDIUM 5.3
CVE-2020-26139EPSS 6%

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s…

Patch available
Fix from $1,600 2021-05-11
Debian Linux MEDIUM 5.3
CVE-2021-30158

An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi…

Fix: 1.31.12 / 1.35.2+
Fix from $1,600 2021-04-06
Debian Linux MEDIUM 5.3
CVE-2020-28896

Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was inva…

Fix: 2.0.2 / 2020-11-20+
Fix from $1,600 2020-11-23
Debian Linux CRITICAL 9.8
CVE-2019-20933EPSS 31%

InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha…

Fix: 1.7.6+
Fix from $2,300 2020-11-19
Debian Linux CRITICAL 9.8
CVE-2020-25592EPSS 58%

In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH.

Fix: 2015.8.10 / 2015.8.13+
Fix from $2,300 2020-11-06
Debian Linux CRITICAL 9.8
CVE-2014-8650

python-requests-Kerberos through 0.5 does not handle mutual authentication

Fix: after 0.5
Fix from $2,300 2019-12-15
Debian Linux CRITICAL 9.8
CVE-2019-11187

Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t…

Fix: after 2019-04-11
Fix from $2,300 2019-08-15
Debian Linux MEDIUM 6.5
CVE-2018-0505

Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock

Fix: 1.31.1+
Fix from $1,600 2018-10-04
Debian Linux CRITICAL 9.8
CVE-2018-16947

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not…

Fix: 1.6.23 / 1.8.2+
Fix from $2,300 2018-09-12
Debian Linux CRITICAL 9.8
CVE-2017-0356

A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker …

Fix: 3.20170111+
Fix from $2,300 2018-04-13
Debian Linux MEDIUM 5.3
CVE-2016-9646

ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),…

Fix: 3.20161229+
Fix from $1,600 2018-04-13
Debian Linux HIGH 8.1
CVE-2017-1000433

pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k…

Fix: after 4.4.0
Fix from $1,950 2018-01-02
Debian Linux HIGH 8.1
CVE-2017-8028

In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind…

Mitigation only
Fix from $1,950 2017-11-27
Debian Linux CRITICAL 9.8
CVE-2017-16613EPSS 8%

An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and …

Fix: after 2.15.1
Fix from $2,300 2017-11-21
Debian Linux MEDIUM 6.5
CVE-2017-7650

In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem…

Fix: 1.4.12+
Fix from $1,600 2017-09-11
Debian Linux CRITICAL 9.8
CVE-2015-7871EPSS 82%

Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Debian Linux CRITICAL 9.8
CVE-2016-1908EPSS 14%

The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr…

Patch available
Fix from $2,300 2017-04-11
Debian Linux CRITICAL 9.8
CVE-2016-4422

The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg…

Mitigation only
Fix from $2,300 2016-05-06
Debian Linux HIGH 7.7
CVE-2015-7974EPSS 6%

NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot…

Fix: 4.2.8 / 4.3.90+
Fix from $1,950 2016-01-26
Debian Linux MEDIUM 5.0
CVE-2013-6890EPSS 9%

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in…

Mitigation only
Fix from $1,600 2013-12-23