When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2012-3473
Ushahidi Platform < 2.5 - Unauthenticated Report Creation and Comment Organization via API
CVE-2012-3472
Ushahidi Platform < 2.5 - Unauthenticated Email API Access
CVE-2012-2963
BreakingPoint Storm <3.0 - Info Disclosure
CVE-2012-3424
Ruby on Rails 3.x < 3.0.16, 3.1.x < 3.1.7, 3.2.x < 3.2.7 - Denial of Service via Digest Authentication String Conversion
CVE-2012-2498
Cisco AnyConnect Secure Mobility Client 3.0-3.0.08066 - Improper Authentication via Crafted Certificate
CVE-2012-3408
Puppet < 2.7.18 and Puppet Enterprise < 2.5.2 - Improper Authentication via IP Address Spoofing
CVE-2012-2626
Plixer Scrutinizer < 9.5.0 - Unauthenticated Administrative Account Creation via admin.cgi userprefs Action
CVE-2012-3885
AirDroid 1.0.4 beta - Improper Authentication via Weak Default Password
CVE-2012-3884
AirDroid 1.0.4 beta - Improper Authentication via Password Hash Replay
CVE-2012-3356
ViewVC < 1.1.15 - Improper Authentication
CVE-2012-2974
SMC SMC8024L2 Switch - Unauthenticated Authentication Bypass via Direct HTML File Access
CVE-2012-2351
Mahara <1.4.2 - Auth Bypass
CVE-2012-0301
Symantec Message Filter 6.3 - Session Fixation
CVE-2012-2281
RSA Access Manager Agent and Server - Improper Session Token Validation
CVE-2012-1123
MantisBT < 1.2.9 - Unauthenticated Authentication Bypass via Null Password
CVE-2012-2388
strongSwan 4.2.0-4.6.3 - Authentication Bypass via Empty or Zeroed RSA Signature
CVE-2012-2122
Oracle MySQL 5.1.x < 5.1.63, 5.5.x < 5.5.24, 5.6.x < 5.6.6 - Authentication Bypass via Repeated Failed Authentication
CVE-2012-0717
IBM WebSphere App Server <7.0.0.23 - Auth Bypass
CVE-2012-1145
Red Hat Satellite 5.4 - Unauthenticated Denial of Service via Package Upload
CVE-2012-2606
Bradford Network Sentry <5.3.3 - Info Disclosure
CVE-2012-0944
aptdaemon < 0.43 - Unauthenticated Arbitrary Package Installation via Man-in-the-Middle
CVE-2012-2562
Xelex MobileTrack < 2.3.7 - Unauthenticated Command Execution via SMS
CVE-2012-0675
Apple Mac OS X <10.7.4 - Info Disclosure
CVE-2012-0335
Cisco Adaptive Security Appliance Software 7.2-8.4 - Improper Authentication
CVE-2012-0333
Cisco Small Business IP Phone Firmware < 7.4.9 - Unauthenticated Push XML Request Handling
Details
Vulnerabilities
4,376
Exploit Likelihood
High