Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,805 CVEs tagged with CWE-284739 Critical, 1,944 High, 2,579 Medium, 530 Low, 13 Unrated.

CVE-2016-9816

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9815

Published Feb 27, 2017

Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8986

Published Feb 22, 2017

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8915

Published Feb 22, 2017

IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9378

Published Feb 22, 2017

Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial o…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6077

Published Feb 15, 2017

IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document. IBM Reference #: 1991584.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10223

Published Feb 14, 2017

An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "c…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9356

Published Feb 13, 2017

An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5801

Published Feb 13, 2017

An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacker to gain access by brute forc…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7565

Published Feb 13, 2017

install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10026

Published Feb 13, 2017

ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins and the CGI interface enabled, w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8832

Published Feb 9, 2017

Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "mana…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0308

Published Feb 8, 2017

IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0214

Published Feb 8, 2017

IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a malicious file. The only way th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8418

Published Feb 8, 2017

A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9639

Published Feb 7, 2017

Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,101-5,125 of 5,805 CVEsPage 205 of 233