Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2015-7490

Published Mar 3, 2016

IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended acces…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-2278

Published Mar 2, 2016

Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary O…

CVSS 7.2 · High

CVE-2016-0225

Published Feb 29, 2016

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1315

Published Feb 12, 2016

The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass i…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2048

Published Feb 8, 2016

Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8361

Published Feb 8, 2016

Multiple unspecified services in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 do not require authentication, which allows remote attackers to obtain sensitive informatio…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-1905

Published Feb 3, 2016

The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2049

Published Feb 1, 2016

examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1492

Published Jan 26, 2016

The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier for remote attackers to obtai…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-6317

Published Jan 23, 2016

Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-8512

Published Jan 9, 2016

The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obta…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6862

Published Jan 8, 2016

HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1985

Published Jan 3, 2016

The queue manager on IBM MQ M2000 appliances before 8.0.0.4 allows local users to bypass an intended password requirement and read private keys by leveraging the existence of a st…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-6851

Published Dec 23, 2015

EMC RSA SecurID Web Agent before 8.0 allows physically proximate attackers to bypass the privacy-screen protection mechanism by leveraging an unattended workstation and running DO…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1836

Published Dec 21, 2015

Apache HBase 0.98 before 0.98.12.1, 1.0 before 1.0.1.1, and 1.1 before 1.1.0.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, uses incorrect…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2015-7055

Published Dec 11, 2015

AppleMobileFileIntegrity in Apple iOS before 9.2 and tvOS before 9.1 does not prevent changes to access-control structures, which allows attackers to execute arbitrary code in a p…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-6848

Published Nov 27, 2015

EMC Isilon OneFS 7.1.x before 7.1.1.5, 7.2.0.x before 7.2.0.3, and 7.2.1.x before 7.2.1.1, when the RFC 2307 feature is configured but SFU is not universally present, allows remot…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,401-5,425 of 5,607 CVEsPage 217 of 225