CWE-290

Authentication Bypass by Spoofing

Parent: CWE-1390 - Weak Authentication

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

637 vulnerabilities with CWE-290
CVE-2017-18190 HIGH
CUPS < 2.2.2 - Remote IPP Command Execution via DNS Rebinding
CVSS 7.5
CVE-2017-16897 HIGH
Auth0 passport-wsfed-saml2 <3.0.5 - Privilege Escalation
CVSS 8.1
CVE-2017-14487 CRITICAL
OhMiBod Remote < 2.50.37 - Authentication Bypass via Shared Preferences Manipulation
CVSS 9.1
CVE-2017-12096 MEDIUM
Circle with Disney - Info Disclosure
CVSS 6.5
CVE-2017-14375 CRITICAL
EMC Unisphere <8.4.0.15-1.4 - Auth Bypass
CVSS 9.8
CVE-2017-14003 CRITICAL
LAVA ESL <6.01.00-29.03.2007 - Auth Bypass
CVSS 9.8
CVE-2017-11717 HIGH
MetInfo <= 5.3.17 - Authentication Bypass via CAPTCHA Reuse
CVSS 7.5
CVE-2017-8422 HIGH
KDE kdelibs < 4.14.32 and KAuth < 5.34 - Authentication Bypass via CallerID Spoofing
CVSS 7.8
CVE-2017-6405 HIGH
Veritas NetBackup < 8.0 and NetBackup Appliance < 3.0 - Authentication Bypass via DNS Spoofing
CVSS 7.5
CVE-2013-5661 MEDIUM
BIND >=9.8.0 <9.9.0 - Cache Poisoning via DNS Response Rate Limiting
CVSS 5.9
CVE-2009-1048 CRITICAL
snom 300/320/360/370/820 Firmware 6.5-6.5.20 - Authentication Bypass via Host Header Spoofing
CVSS 9.8
CVE-1999-0012 HIGH
Microsoft FrontPage - Authentication Bypass via Long Filename
CVSS 7.0
Details
Vulnerabilities 637