Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2016-1699

Published Jun 5, 2016

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remot…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1697

Published Jun 5, 2016

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1696

Published Jun 5, 2016

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspec…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1694

Published Jun 5, 2016

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof we…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1693

Published Jun 5, 2016

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1692

Published Jun 5, 2016

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1682

Published Jun 5, 2016

The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.27…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2016-1676

Published Jun 5, 2016

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass t…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1675

Published Jun 5, 2016

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruc…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-1672

Published Jun 5, 2016

The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which al…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-4810

Published Jun 1, 2016

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the Xen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4502

Published May 31, 2016

Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier allows remote attackers to bypass intended access restrictions and execute arbitrary functions via a…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4501

Published May 31, 2016

Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote attackers to bypass authentication and make arbitrary config…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1999

Published May 30, 2016

The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Col…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-2159

Published May 22, 2016

The save_submission function in mod/assign/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 allows re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3728

Published May 20, 2016

Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote attackers to execute arbitrary co…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2100

Published May 20, 2016

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1) edit_bookmarks or (2) destro…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1844

Published May 20, 2016

The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1806

Published May 20, 2016

Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1805

Published May 20, 2016

CoreStorage in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1797

Published May 20, 2016

Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbitrary code in a privileged con…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0731

Published May 18, 2016

The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,301-5,325 of 5,607 CVEsPage 213 of 225