Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2015-6928

Published Sep 28, 2015

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7306

Published Sep 21, 2015

The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by lever…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5861

Published Sep 18, 2015

SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5838

Published Sep 18, 2015

SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5826

Published Sep 18, 2015

WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1173

Published Sep 16, 2015

Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-6675

Published Sep 11, 2015

Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traff…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-4302

Published Aug 19, 2015

The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CS…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5512

Published Aug 18, 2015

The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5502

Published Aug 18, 2015

The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0277

Published Aug 17, 2015

The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attac…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5746

Published Aug 17, 2015

AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3806

Published Aug 17, 2015

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3757

Published Aug 16, 2015

Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3155

Published Aug 14, 2015

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3213

Published Aug 12, 2015

The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5960

Published Aug 8, 2015

Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB i…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5623

Published Aug 3, 2015

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leve…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3224

Published Jul 26, 2015

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2847

Published Jul 26, 2015

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removi…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 5,451-5,475 of 5,607 CVEsPage 219 of 225