Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2014-9422

Published Feb 19, 2015

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remot…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8757

Published Feb 17, 2015

LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-0008

Published Feb 11, 2015

The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold…

CVSS 8.3 · High
evidence mentions
3
Buzz score
20.4

CVE-2015-0926

Published Feb 1, 2015

Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a script file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8833

Published Jan 30, 2015

SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cache, which allows local users to read search results associat…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-8827

Published Jan 30, 2015

LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtai…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-1376

Published Jan 28, 2015

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an up…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9648

Published Jan 27, 2015

components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9197

Published Jan 27, 2015

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote atta…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2015-1307

Published Jan 26, 2015

plasma-workspace before 5.1.95 allows remote attackers to obtain passwords via a Trojan horse Look and Feel package.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9572

Published Jan 26, 2015

MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the inst…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-1449

Published Dec 25, 2014

The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses the history API.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7193

Published Dec 25, 2014

The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which allows remote attackers to obtai…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9388

Published Dec 17, 2014

bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8632

Published Dec 11, 2014

The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8631

Published Dec 11, 2014

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1589

Published Dec 11, 2014

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypass intended access restrictions…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-8680

Published Dec 11, 2014

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the la…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-6319

Published Dec 11, 2014

Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,551-5,575 of 5,607 CVEsPage 223 of 225