When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,374 vulnerabilities with CWE-287
CVE-2012-4456
OpenStack Keystone < 2012.1.2 - Improper Authentication via X-Auth-Token Validation
CVE-2012-5309
IBM Lotus Notes Traveler <8.5.3.3 - Auth Bypass
CVE-2012-3520
Linux Kernel < 3.2.30 - Improper Authentication via Netlink Messages
CVE-2012-1602
NextBBS 0.6 - Unauthenticated Authentication Bypass via userkey Cookie
CVE-2012-3492
Condor 7.6.x < 7.6.10 and 7.8.x < 7.8.4 - Improper Authentication via Weak Directory Permissions
CVE-2012-2287
RSA Authentication Agent 7.1 and Authentication Client 3.5 - Authenticated Token Authentication Bypass
CVE-2012-3137
Oracle Database Server - Info Disclosure
CVE-2012-3741
iPhone OS < 6 - Unauthenticated Parental Controls Bypass via Purchase Transaction
CVE-2012-3721
macOS < 10.7.5 - Unauthenticated Device Enumeration via Device Management Interface
CVE-2012-5003
No Machine NX Web Companion <3 - RCE
CVE-2012-4926
Img Pals Photo Host 1.0 - Unauthenticated Administrator Activation Change via approve.php u Parameter
CVE-2012-2983
Webmin < 1.590 - Unauthenticated Arbitrary File Read via file/edit_html.cgi
CVE-2012-4392
owncloud_server - Authentication Bypass via oc_token Cookie
CVE-2012-4741
PacketFence < 3.2.0 - Improper Authentication via RADIUS User-Name Attribute
CVE-2012-2285
EMC Cloud Tiering Appliance < 9.0 - Unauthenticated GUI Admin Access via Crafted Auth File
CVE-2012-3467
Apache QPID <= 0.16 - Unauthenticated Authentication Bypass via NullAuthenticator
CVE-2012-3416
Condor < 7.8.2 - Unauthenticated Host-Based Authentication Bypass via Spoofed Reverse DNS
CVE-2012-4604
Websense Web Security <7.6.24 - Auth Bypass
CVE-2012-4599
McAfee SmartFilter Administration < 4.2.1 - Unauthenticated Remote Code Execution via JBoss RMI Interface
CVE-2012-4595
McAfee EWS <5.5.6 & MEG <7.0.2 - Auth Bypass
CVE-2012-4581
McAfee EWS <5.5.6 & MEG 7.0 <1 - Auth Bypass
CVE-2012-2132
libsoup <= 2.32.2 - Improper Authentication via SSL Certificate Validation Bypass
CVE-2012-3024
Tridium Niagara AX Framework <3.6 - Auth Bypass
CVE-2012-3473
Ushahidi Platform < 2.5 - Unauthenticated Report Creation and Comment Organization via API
CVE-2012-3472
Ushahidi Platform < 2.5 - Unauthenticated Email API Access
Details
Vulnerabilities
4,374
Exploit Likelihood
High