Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthenticationCWE-287 × clear
MEDIUM 6.5 CVE-2023-52160 The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to… Debian Linux after 2.10 Fix from $1,6002024-02-22 HIGH 7.5 CVE-2021-36369 An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH … Debian Linux after 2020.81 Fix from $1,9502022-10-12 MEDIUM 6.5 CVE-2022-2553 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes … Debian Linux after 1.0 Fix from $1,6002022-07-28 CRITICAL 9.8 CVE-2021-40874 An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When using the RESTServer plug-in to operate a REST password validation service (… Debian Linux Patch available Fix from $2,3002022-07-18 HIGH 8.8 CVE-2022-30550 An issue was discovered in the auth component in Dovecot 2.2 and 2.3 before 2.3.20. When two passdb configuration entries exist with the same driver … Debian Linux 2.4.0+ Fix from $1,9502022-07-17 HIGH 8.8 CVE-2022-1049 A flaw was found in the Pacemaker configuration tool (pcs). The pcs daemon was allowing expired accounts, and accounts with expired passwords to logi… Debian Linux after 0.11.2 Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2022-0730 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. Debian Linux No fix yet Fix from $2,3002022-03-03 HIGH 7.2 CVE-2020-25719 A flaw was found in the way Samba, as an Active Directory Domain Controller, implemented Kerberos name-based authentication. The Samba AD DC, could b… Debian Linux Patch available Fix from $1,9502022-02-18 MEDIUM 5.9 CVE-2016-2124 A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the w… Debian Linux Patch available Fix from $1,6002022-02-18 CRITICAL 9.1 CVE-2021-3850 Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. Debian Linux after 5.20.21 Fix from $2,3002022-01-25 MEDIUM 5.3 CVE-2020-26139EPSS 6% An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet s… Debian Linux Patch available Fix from $1,6002021-05-11 MEDIUM 5.3 CVE-2021-30158 An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. Thi… Debian Linux 1.31.12 / 1.35.2+ Fix from $1,6002021-04-06 MEDIUM 5.3 CVE-2020-28896 Mutt before 2.0.2 and NeoMutt before 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was inva… Debian Linux 2.0.2 / 2020-11-20+ Fix from $1,6002020-11-23 CRITICAL 9.8 CVE-2019-20933EPSS 31% InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may ha… Debian Linux 1.7.6+ Fix from $2,3002020-11-19 CRITICAL 9.8 CVE-2020-25592EPSS 58% In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authentication and invoke Salt SSH. Debian Linux 2015.8.10 / 2015.8.13+ Fix from $2,3002020-11-06 CRITICAL 9.8 CVE-2014-8650 python-requests-Kerberos through 0.5 does not handle mutual authentication Debian Linux after 0.5 Fix from $2,3002019-12-15 CRITICAL 9.8 CVE-2019-11187 Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing t… Debian Linux after 2019-04-11 Fix from $2,3002019-08-15 MEDIUM 6.5 CVE-2018-0505 Mediawiki 1.31 before 1.31.1, 1.30.1, 1.29.3 and 1.27.5 contains a flaw where BotPasswords can bypass CentralAuth's account lock Debian Linux 1.31.1+ Fix from $1,6002018-10-04 CRITICAL 9.8 CVE-2018-16947 An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not… Debian Linux 1.6.23 / 1.8.2+ Fix from $2,3002018-09-12 CRITICAL 9.8 CVE-2017-0356 A flaw, similar to to CVE-2016-9646, exists in ikiwiki before 3.20170111, in the passwordauth plugin's use of CGI::FormBuilder, allowing an attacker … Debian Linux 3.20170111+ Fix from $2,3002018-04-13 MEDIUM 5.3 CVE-2016-9646 ikiwiki before 3.20161229 incorrectly called the CGI::FormBuilder->field method (similar to the CGI->param API that led to Bugzilla's CVE-2014-1572),… Debian Linux 3.20161229+ Fix from $1,6002018-04-13 HIGH 8.1 CVE-2017-1000433 pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to log in as any user without k… Debian Linux after 4.4.0 Fix from $1,9502018-01-02 HIGH 8.1 CVE-2017-8028 In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP Bind… Debian Linux Mitigation only Fix from $1,9502017-11-27 CRITICAL 9.8 CVE-2017-16613EPSS 8% An issue was discovered in middleware.py in OpenStack Swauth through 1.2.0 when used with OpenStack Swift through 2.15.1. The Swift object store and … Debian Linux after 2.15.1 Fix from $2,3002017-11-21 MEDIUM 6.5 CVE-2017-7650 In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or rem… Debian Linux 1.4.12+ Fix from $1,6002017-09-11 CRITICAL 9.8 CVE-2015-7871EPSS 82% Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. Debian Linux 4.2.8 / 4.3.77+ Fix from $2,3002017-08-07 CRITICAL 9.8 CVE-2016-1908EPSS 14% The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-contr… Debian Linux Patch available Fix from $2,3002017-04-11 CRITICAL 9.8 CVE-2016-4422 The pam_sm_authenticate function in pam_sshauth.c in libpam-sshauth might allow context-dependent attackers to bypass authentication or gain privileg… Debian Linux Mitigation only Fix from $2,3002016-05-06 HIGH 7.7 CVE-2015-7974EPSS 6% NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remot… Debian Linux 4.2.8 / 4.3.90+ Fix from $1,9502016-01-26 MEDIUM 5.0 CVE-2013-6890EPSS 9% denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (in… Debian Linux Mitigation only Fix from $1,6002013-12-23