Total
3371 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-4552 | 1 Drupalauth Project | 1 Drupalauth | 2024-11-21 | 7.5 HIGH | N/A |
lib/Auth/Source/External.php in the drupalauth module before 1.2.2 for simpleSAMLphp allows remote attackers to authenticate as an arbitrary user via the user name (uid) in a cookie. | |||||
CVE-2013-4471 | 1 Openstack | 1 Horizon | 2024-11-21 | 5.5 MEDIUM | N/A |
The Identity v3 API in OpenStack Dashboard (Horizon) before 2013.2 does not require the current password when changing passwords for user accounts, which makes it easier for remote attackers to change a user password by leveraging the authentication token for that user. | |||||
CVE-2013-4462 | 1 Portable Phpmyadmin Project | 1 Portable Phpmyadmin | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability | |||||
CVE-2013-4454 | 1 Getbutterfly | 1 Portable-phpmyadmin | 2024-11-21 | 6.4 MEDIUM | 9.1 CRITICAL |
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities | |||||
CVE-2013-4435 | 1 Saltstack | 1 Salt | 2024-11-21 | 6.0 MEDIUM | N/A |
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine. | |||||
CVE-2013-4304 | 2 Brion Vibber, Mediawiki | 2 Centralauth Extension, Mediawiki | 2024-11-21 | 7.5 HIGH | N/A |
The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password. | |||||
CVE-2013-4178 | 2 Drupal, Google Authenticator Login Project | 2 Drupal, Ga Login | 2024-11-21 | 5.0 MEDIUM | N/A |
The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to obtain access by replaying the username, password, and one-time password (OTP). | |||||
CVE-2013-4061 | 1 Ibm | 1 Rational Policy Tester | 2024-11-21 | 4.0 MEDIUM | N/A |
IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors. | |||||
CVE-2013-4001 | 1 Ibm | 1 Cognos Command Center | 2024-11-21 | 4.3 MEDIUM | N/A |
Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie. | |||||
CVE-2013-3977 | 1 Ibm | 1 Sametime | 2024-11-21 | 4.3 MEDIUM | N/A |
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine which meeting rooms are owned by a user by leveraging knowledge of valid user names. | |||||
CVE-2013-3659 | 1 Nttdocomo | 1 Overseas Usage | 2024-11-21 | 3.3 LOW | N/A |
The NTT DOCOMO overseas usage application 2.0.0 through 2.0.4 for Android does not properly connect to Wi-Fi access points, which allows remote attackers to obtain sensitive information by leveraging presence in an 802.11 network's coverage area. | |||||
CVE-2013-3656 | 1 Cybozu | 1 Cybozu Office | 2024-11-21 | 5.8 MEDIUM | N/A |
Cybozu Office 9.1.0 and earlier does not properly manage sessions, which allows remote attackers to bypass authentication by leveraging knowledge of a login URL. | |||||
CVE-2013-3613 | 1 Dahuasecurity | 65 Dvr0404hd-a, Dvr0404hd-l, Dvr0404hd-s and 62 more | 2024-11-21 | 7.8 HIGH | N/A |
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port. | |||||
CVE-2013-3610 | 1 Asus | 2 Rt-n10e, Rt-n10e Firmware | 2024-11-21 | 6.1 MEDIUM | N/A |
qis/QIS_finish.htm on the ASUS RT-N10E router with firmware before 2.0.0.25 does not require authentication, which allows remote attackers to discover the administrator password via a direct request. | |||||
CVE-2013-3586 | 1 Samsung | 2 Dvr, Smart Viewer | 2024-11-21 | 7.6 HIGH | N/A |
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie. | |||||
CVE-2013-3581 | 1 Choice Wireless | 1 Wixfmr-111 | 2024-11-21 | 7.1 HIGH | N/A |
ajax.cgi in the web interface on the Choice Wireless Green Packet WIXFMR-111 4G WiMax modem allows remote attackers to obtain sensitive information via an Ajax (1) wmxState or (2) netState request. | |||||
CVE-2013-3473 | 1 Cisco | 1 Prime Central For Hosted Collaboration Solution Assurance | 2024-11-21 | 7.8 HIGH | N/A |
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote attackers to discover usernames and passwords via an HTTP request, aka Bug ID CSCud32600. | |||||
CVE-2013-3466 | 1 Cisco | 1 Secure Access Control Server | 2024-11-21 | 9.3 HIGH | N/A |
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636. | |||||
CVE-2013-3431 | 1 Cisco | 1 Video Surveillance Manager | 2024-11-21 | 7.8 HIGH | N/A |
Cisco Video Surveillance Manager (VSM) before 7.0.0 does not require authentication for access to VSMC monitoring pages, which allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv40169. | |||||
CVE-2013-3430 | 1 Cisco | 1 Video Surveillance Manager | 2024-11-21 | 9.0 HIGH | N/A |
Cisco Video Surveillance Manager (VSM) before 7.0.0 allows remote attackers to obtain sensitive configuration, archive, and log information via unspecified vectors, related to the Cisco_VSBWT (aka Broadware sample code) package, aka Bug ID CSCsv37288. |