Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,612 CVEs tagged with CWE-284701 Critical, 1,857 High, 2,521 Medium, 519 Low, 14 Unrated.

CVE-2016-0279

Published Jun 26, 2016

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a cra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0278

Published Jun 26, 2016

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a cra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0277

Published Jun 26, 2016

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a cra…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7473

Published Jun 26, 2016

runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-1190

Published Jun 25, 2016

Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4811

Published Jun 19, 2016

The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API ac…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4813

Published Jun 19, 2016

NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3698

Published Jun 13, 2016

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-…

CVSS 8.1 · High

CVE-2016-5302

Published Jun 13, 2016

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4911

Published Jun 13, 2016

The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass inte…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1543

Published Jun 13, 2016

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4524

Published Jun 10, 2016

ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2150

Published Jun 9, 2016

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

CVSS 7.1 · High
Showing 5,276-5,300 of 5,612 CVEsPage 212 of 225