When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
4,376 vulnerabilities with CWE-287
CVE-2009-3966
Arcade Trade Script 1.0 - Auth Bypass
CVE-2009-3923
VirtualBox <2.0.8-2.0.10 - Info Disclosure
CVE-2009-3862
Novell eDirectory <8.7.3.10-8.8.5 - DoS
CVE-2009-3635
TYPO3 < 4.0.12, 4.1.x < 4.1.13, 4.2.x < 4.2.10, 4.3.x < 4.3beta2 - Improper Authentication via Install Tool
CVE-2009-3623
Linux Kernel < 2.6.31.2 - Denial of Service via NFSv4 AUTH_NULL Credentials Cache Access
CVE-2009-3828
Everfocus EDR1600 - Unauthenticated Authentication Bypass
CVE-2009-3657
Shared Sign-On 5.x and 6.x - Session Fixation
CVE-2009-3481
iCRM Basic (com_icrmbasic) 1.4.2.31 - Improper Authentication
CVE-2009-3441
OSSIM < 2.1.2 - Unauthenticated Authentication Bypass via Direct Request
CVE-2009-2863
Cisco IOS 12.0-12.4 - Unauthenticated Authentication Bypass via Firewall Authentication Proxy Race Condition
CVE-2009-3423
Zenas PaoLink 1.0 - Unauthenticated Authentication Bypass via login_ok Parameter
CVE-2009-3422
Zenas PaoLiber 1.1 - Unauthenticated Authentication Bypass via login_ok Parameter
CVE-2009-3421
CRITICAL
Zenas PaoBacheca Guestbook 2.1 - Unauthenticated Authentication Bypass via login_ok Parameter
CVSS 9.8
CVE-2009-3261
LiveStreet 0.2 - Unauthenticated SQL Injection via Update Script
CVE-2009-3232
Ubuntu Linux - Improper Authentication via Empty PAM Module Selection
CVE-2009-3231
PostgreSQL 8.2-8.2.14 and 8.3-8.3.8 - Unauthenticated Authentication Bypass via Empty LDAP Password
CVE-2009-3158
simplePHPWeb 0.2 - Unauthenticated Administrative Access via admin/files.php
CVE-2009-3107
Symantec Altiris Deployment Solution < 6.9 SP3 Build 430 - Authentication Bypass
CVE-2009-2697
Red Hat GDM <2.16.0-56 - Auth Bypass
CVE-2009-1878
Adobe ColdFusion < 8.0.1 - Session Fixation
CVE-2009-2088
IBM WebSphere Application Server <7.0.0.5 - Auth Bypass
CVE-2009-2085
IBM WebSphere Application Server <6.1.0.25-7.0.0.5 - Auth Bypass
CVE-2009-0906
IBM WebSphere Application Server SCA Feature Pack < 1.0.0.3 - Authenticated Authentication Bypass
CVE-2009-0669
Zope Object Database < 3.8.2 - Authentication Bypass via ZEO Network Protocol
CVE-2009-2410
sssd 0.4.1 - Improper Authentication via Blank-Password Account Handling
Details
Vulnerabilities
4,376
Exploit Likelihood
High