When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2010-3896
IBM OmniFind Enterprise Edition 8.x/9.x - Unauthenticated Server Configuration Modification
CVE-2010-4211
PayPal < 3.0 - Improper Certificate Validation
CVE-2010-3852
Luci < 0.22.4 - Unauthenticated Authentication Bypass via Forged Ticket Cookie
CVE-2010-4121
IBM Tivoli Provisioning Manager 7.1.1.3 - Unauthenticated SQL Command Execution
CVE-2010-3739
IBM DB2 Universal Database < 9.5 - Improper Authentication via Audit Settings Bypass
CVE-2010-3686
Drupal OpenID Module < 6.18 and 5.x-1.4 - Authentication Bypass via Unsigned OpenID Fields
CVE-2010-3685
Drupal OpenID Module - Authentication Bypass via OpenID Response Nonce Reuse
CVE-2010-3091
Drupal <6.18 & <5.x-1.4 - Auth Bypass
CVE-2010-1820
Apple Mac OS X 10.6.x-10.6.4 - Unauthenticated AFP Server Shared-Folder Access Bypass
CVE-2010-3471
IBM FileNet P8 AE <4.0.2.7 - Info Disclosure
CVE-2010-2731
Microsoft IIS 5.1 on Windows XP SP3 - Directory Authentication Bypass via Crafted Request
CVE-2010-2940
SSSD 1.3.0 - Unauthenticated Authentication Bypass via Empty Password
CVE-2010-1802
libsecurity - Improper Certificate Domain Validation
CVE-2010-2944
zope-ldapuserfolder <2.9-1 - Privilege Escalation
CVE-2010-0834
Base-files <5.0.0ubuntu7.1-5.0.0ubuntu20.10.04.2 - RCE
CVE-2010-2526
LVM2 < 2.02.72 - Unauthenticated Denial of Service via Crafted Control Commands
CVE-2010-2927
IBM Tivoli Directory Server <6.0.0.8-TIV-ITDS-IF0006 - DoS
CVE-2010-0833
Likewise Open/CIFS <6.0.8234 - Auth Bypass
CVE-2010-2668
Adaptive Micro Systems ALPHA Ethernet Adapter II Web-Manager 3.40.2 - Authentication Bypass
CVE-2010-1670
Mahara < 1.0.15, 1.1.x < 1.1.9, 1.2.x < 1.2.5 - Unauthenticated Authentication Bypass via Empty Password
CVE-2010-2620
Open-FTPD < 1.2 - Unauthenticated Authentication Bypass via FTP Command Injection
CVE-2010-1375
Apple Mac OS X 10.5.8 - Privilege Escalation
CVE-2010-2149
Fujitsu e-Pares V01 L01, L03, L10, L20, L30 - Session Fixation
CVE-2010-2026
Cisco Scientific Atlanta WebSTAR DPC2100R2 - Unauthenticated Authentication Bypass
CVE-2010-1454
VMware SpringSource tc Server Runtime <6.0.20.D-6.0.25.A-SR01 - RCE
Details
Vulnerabilities
4,376
Exploit Likelihood
High