← Back
CWE-287

4,461 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

JSON object

Loading...

CVEs (4,461)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Sep 16, 2008
N/A· v4
N/A· v3
6.3 MEDIUM· v2
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authen...Show more
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same login screen.Show less
1Apple
2Mac Os X
Mac Os X Server
Apr 23, 2026
Sep 16, 2008
N/A· v4
N/A· v3
7.6 HIGH· v2
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login t...Show more
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.Show less
1Stash
1Stash
Apr 23, 2026
Sep 15, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.
1Ruby Lang
1Ruby
Apr 23, 2026
Sep 4, 2008
N/A· v4
N/A· v3
5.8 MEDIUM· v2
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remot...Show more
resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.Show less
1Google
1Google Apps
Apr 23, 2026
Sep 3, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and...Show more
The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and recipient field.Show less
1Spacetag
1Lacoodast
Apr 23, 2026
Aug 27, 2008
N/A· v4
9.1 CRITICAL· v3
6.8 MEDIUM· v2
Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors.
1Microworld Technologies
1Mailscan
Apr 23, 2026
Aug 20, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or...Show more
Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.Show less
1Symantec
1Veritas Storage Foundation
Apr 23, 2026
Aug 18, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows re...Show more
The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.Show less
1Calacode
1Atmail
Apr 23, 2026
Aug 10, 2008
N/A· v4
N/A· v3
7.8 HIGH· v2
Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the e...Show more
Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating and downloading a backup archive of the entire @Mail directory tree. NOTE: this can be leveraged for remote exploitation of CVE-2008-3395. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Mpfm
1Mask Php File Manager
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in mask PHP File Manager (mPFM) before 2.3 has unknown impact and remote attack vectors related to "manipulation of cookies."
1Webgui
1Plain Black Webgui
Apr 23, 2026
Aug 6, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RSSFromParent in Plain Black WebGUI before 7.5.13 does not restrict view access to Collaboration System (CS) RSS feeds, which allows remote attackers to obtain sensitive information (CS data).
1Phpfreechat
1Phpfreechat
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.
1Sun
2Java System Web Server Plugin
N1 Service Provisioning System
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unk...Show more
Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors.Show less
1Axesstel
1Akw D800
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi,...Show more
The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi, and (5) cgi-bin/route.cgi, which allows remote attackers to change the modem's configuration via direct requests.Show less
1Phplinkat
1Phplinkat
Apr 23, 2026
Jul 31, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.
1Jamroom
1Jamroom
Apr 23, 2026
Jul 30, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie co...Show more
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.Show less
1Maian
1Recipe
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary recipe_cookie cookie.
1Maian Script World
1Maian Uploader
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie.
1Maian
1Guestbook
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary gbook_cookie cookie.
1Maian
1Links
Apr 23, 2026
Jul 25, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary links_cookie cookie.