Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,317 CVEs tagged with CWE-863317 Critical, 1,148 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2016-4572

Published Nov 26, 2019

In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3131

Published Nov 26, 2019

Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5879

Published Nov 25, 2019

Insufficient policy enforcement in extensions in Google Chrome prior to 77.0.3865.75 allowed an attacker who convinced a user to install a malicious extension to read local files…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5864

Published Nov 25, 2019

Insufficient data validation in CORS in Google Chrome prior to 76.0.3809.87 allowed an attacker who convinced a user to install a malicious extension to bypass content security po…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-13716

Published Nov 25, 2019

Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-16538

Published Nov 21, 2019

A sandbox bypass vulnerability in Jenkins Script Security Plugin 1.67 and earlier related to the handling of default parameter expressions in closures allowed attackers to execute…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18949

Published Nov 14, 2019

SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections tar…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1070

Published Nov 14, 2019

v86d before 0.1.10 do not verify if received netlink messages are sent by the kernel. This could allow unprivileged users to manipulate the video mode and potentially other conseq…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-5231

Published Nov 13, 2019

P30 smartphones with versions earlier than ELLE-AL00B 9.1.0.186(C00E180R2P1) have an improper authorization vulnerability. The software incorrectly performs an authorization check…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2548

Published Oct 31, 2019

IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-21030

Published Oct 31, 2019

Jupyter Notebook before 5.5.0 does not use a CSP header to treat served files as belonging to a separate origin. Thus, for example, an XSS payload can be placed in an SVG document.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5533

Published Oct 29, 2019

In VMware SD-WAN by VeloCloud versions 3.x prior to 3.3.0, the VeloCloud Orchestrator parameter authorization check mistakenly allows enterprise users to obtain information of Man…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4311

Published Oct 29, 2019

IBM Security Guardium Big Data Intelligence (SonarG) 4.0 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6144

Published Oct 23, 2019

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web protection.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15900

Published Oct 18, 2019

An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. On platforms without strtonum(3), sscanf was used without checking for error cases. In…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14832

Published Oct 15, 2019

A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17191

Published Oct 5, 2019

The Signal Private Messenger application before 4.47.7 for Android allows a caller to force a call to be answered, without callee user interaction, via a connect message. The exis…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 3,051-3,075 of 3,317 CVEsPage 123 of 133