Skip to main content

CWE archive

CWE-285 CVEs

Programmatic archive

1,501 CVEs tagged with CWE-285128 Critical, 402 High, 666 Medium, 305 Low, 0 Unrated.

CVE-2017-0895

Published May 8, 2017

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-0894

Published May 8, 2017

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0892

Published May 8, 2017

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-5063

Published May 2, 2017

The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2689

Published Mar 29, 2017

Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to obtain privileged file system access or…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-2686

Published Mar 29, 2017

Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the web interface at port 10000/TCP and acces…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-9464

Published Mar 28, 2017

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate betwe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7651

Published Feb 20, 2017

An issue was discovered in certain Apple products. iOS before 10.2 is affected. watchOS before 3.1.1 is affected. The issue involves the "Accounts" component, which allows local u…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-8443

Published Jan 12, 2017

Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: Kernel 3.18. Android ID: A-325…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9217

Published Dec 26, 2016

A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9938

Published Dec 12, 2016

An issue was discovered in Asterisk Open Source 11.x before 11.25.1, 13.x before 13.13.1, and 14.x before 14.2.1 and Certified Asterisk 11.x before 11.6-cert16 and 13.x before 13.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7097

Published Oct 16, 2016

The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging th…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0922

Published Sep 18, 2016

EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6825

Published Sep 7, 2016

Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with software b…

CVSS 9.8 · Critical

CVE-2016-4531

Published Jul 28, 2016

Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by le…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1711

Published Jul 23, 2016

WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader o…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-1710

Published Jul 23, 2016

The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a d…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,501 CVEsPage 60 of 61