Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,612 CVEs tagged with CWE-284701 Critical, 1,857 High, 2,521 Medium, 519 Low, 14 Unrated.

CVE-2015-3213

Published Aug 12, 2015

The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5960

Published Aug 8, 2015

Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB i…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5623

Published Aug 3, 2015

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leve…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3224

Published Jul 26, 2015

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2847

Published Jul 26, 2015

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removi…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1922

Published Jul 20, 2015

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4271

Published Jul 15, 2015

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv0060…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1763

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual function…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1761

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3007

Published Jul 14, 2015

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set sy…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1936

Published Jul 14, 2015

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1927

Published Jul 14, 2015

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webco…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1961

Published Jul 13, 2015

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows rem…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4034

Published Jul 6, 2015

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcela…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3692

Published Jul 3, 2015

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local u…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3691

Published Jul 3, 2015

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context v…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,476-5,500 of 5,612 CVEsPage 220 of 225