Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,316 CVEs tagged with CWE-863317 Critical, 1,147 High, 1,600 Medium, 249 Low, 3 Unrated.

CVE-2019-9272

Published Sep 27, 2019

In WiFi, there is a possible leak of WiFi state due to a permissions bypass. This could lead to a local information disclosure which could be used to determine device location wit…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16884

Published Sep 25, 2019

runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount t…

CVSS 7.5 · High

CVE-2016-10996

Published Sep 20, 2019

The optinmonster plugin before 1.1.4.6 for WordPress has incorrect access control for shortcodes because of a nonce leak.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6838

Published Sep 17, 2019

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KN…

CVSS 6.5 · Medium

CVE-2019-6836

Published Sep 17, 2019

A CWE-863: Incorrect Authorization vulnerability exists in U.motion Server (MEG6501-0001 - U.motion KNX server, MEG6501-0002 - U.motion KNX Server Plus, MEG6260-0410 - U.motion KN…

CVSS 7.5 · High

CVE-2019-15729

Published Sep 17, 2019

An issue was discovered in GitLab Community and Enterprise Edition 8.18 through 12.2.1. An internal endpoint unintentionally disclosed information about the last pipeline that ran…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-14995

Published Sep 11, 2019

The /rest/api/1.0/render resource in Jira before version 8.4.0 allows remote anonymous attackers to determine if an attachment with a specific name exists and if an issue key is v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16114

Published Sep 9, 2019

In ATutor 2.2.4, an unauthenticated attacker can change the application settings and force it to use his crafted database, which allows him to gain access to the application. Next…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-14813

Published Sep 6, 2019

A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSA…

CVSS 9.8 · Critical

CVE-2019-2175

Published Sep 5, 2019

In checkAccess of SliceManagerService.java in Android 9, there is a possible permissions check bypass due to incorrect order of arguments. This could lead to local escalation of p…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-8446

Published Aug 23, 2019

The /rest/issueNav/1/issueTable resource in Jira before version 8.3.2 allows remote attackers to enumerate usernames via an incorrect authorisation check.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8445

Published Aug 23, 2019

Several worklog rest resources in Jira before version 7.13.7, and from version 8.0.0 before version 8.3.2 allow remote attackers to view worklog time information via a missing per…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1192

Published Aug 14, 2019

A security feature bypass vulnerability exists when Microsoft browsers improperly handle requests of different origins. The vulnerability allows Microsoft browsers to bypass Same-…

CVSS 4.3 · Medium

CVE-2019-13417

Published Aug 12, 2019

Search Guard versions before 24.0 had an issue that field caps and mapping API leak field names (but not values) for fields which are not allowed for the user when field level sec…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14924

Published Aug 10, 2019

An issue was discovered in GCDWebServer before 3.5.3. The method moveItem in the GCDWebUploader class checks the FileExtension of newAbsolutePath but not oldAbsolutePath. By lever…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20826

Published Aug 9, 2019

The inline-create rest resource in Jira before version 7.12.3 allows authenticated remote attackers to set the reporter in issues via a missing authorisation check.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 3,076-3,100 of 3,316 CVEsPage 124 of 133