Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2016-5493

Published Oct 25, 2016

Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to aff…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5492

Published Oct 25, 2016

Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality and integri…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5491

Published Oct 25, 2016

Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect confidentiality and integrity…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5482

Published Oct 25, 2016

Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confid…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000032

Published Oct 25, 2016

TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-1000031

Published Oct 25, 2016

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2016-3392

Published Oct 14, 2016

The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4286

Published Oct 13, 2016

Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to bypass intended access restri…

CVSS 8.8 · High

CVE-2016-4407

Published Oct 13, 2016

The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspec…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3635

Published Oct 13, 2016

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by le…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8565

Published Oct 13, 2016

Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-6690

Published Oct 10, 2016

The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3925

Published Oct 10, 2016

server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked Wi-Fi usage) via a crafted appl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3923

Published Oct 10, 2016

The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3882

Published Oct 10, 2016

Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7040

Published Oct 7, 2016

Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote au…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5745

Published Oct 5, 2016

F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before H…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-4551

Published Oct 5, 2016

The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5983

Published Oct 5, 2016

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,151-5,175 of 5,607 CVEsPage 207 of 225