Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2022-39889

Published Nov 9, 2022

Improper access control vulnerability in GalaxyWatch4Plugin prior to versions 2.2.11.22101351 and 2.2.12.22101351 allows attackers to access wearable device information.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39887

Published Nov 9, 2022

Improper access control vulnerability in clearAllGlobalProxy in MiscPolicy prior to SMR Nov-2022 Release 1 allows local attacker to configure EDM setting.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-39884

Published Nov 9, 2022

Improper access control vulnerability in IImsService prior to SMR Nov-2022 Release 1 allows local attacker to access to Call information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-31687

Published Nov 9, 2022

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain admi…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-27673

Published Nov 9, 2022

Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-46851

Published Nov 9, 2022

The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-42707

Published Nov 6, 2022

In Mahara 21.04 before 21.04.7, 21.10 before 21.10.5, 22.04 before 22.04.3, and 22.10 before 22.10.0, embedded images are accessible without a sufficient permission check under ce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-39370

Published Nov 3, 2022

GLPI stands for Gestionnaire Libre de Parc Informatique. GLPI is a Free Asset and IT Management Software package that provides ITIL Service Desk features, licenses tracking and so…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-44622

Published Nov 3, 2022

In JetBrains TeamCity version between 2021.2 and 2022.10 access permissions for secure token health items were excessive

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-42814

Published Nov 1, 2022

A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13. An app may be able to access user-sensitive data.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32946

Published Nov 1, 2022

This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2022-32918

Published Nov 1, 2022

This issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. An app may be able to bypass Privacy preferences.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-32904

Published Nov 1, 2022

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, macOS Monterey 12.6. An app may be able to access…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-3780

Published Nov 1, 2022

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-42327

Published Nov 1, 2022

x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by movi…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33757

Published Oct 25, 2022

An authenticated attacker could read Nessus Debug Log file attachments from the web UI without having the correct privileges to do so. This may lead to the disclosure of informati…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,926-3,950 of 5,607 CVEsPage 158 of 225