Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2016-5700

Published Oct 3, 2016

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2,…

CVSS 9.8 · Critical

CVE-2016-5176

Published Sep 29, 2016

Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6826

Published Sep 26, 2016

Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5943

Published Sep 26, 2016

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access restrictions, and read task deta…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5173

Published Sep 25, 2016

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4694

Published Sep 25, 2016

The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untru…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-5283

Published Sep 22, 2016

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insuff…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5273

Published Sep 22, 2016

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary cod…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4464

Published Sep 21, 2016

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might al…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6802

Published Sep 20, 2016

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3366

Published Sep 14, 2016

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-5954

Published Sep 12, 2016

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before CF12 allows remote authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3899

Published Sep 11, 2016

OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not valida…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3898

Published Sep 11, 2016

Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of service (loss of locked-screen…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3884

Published Sep 11, 2016

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 lacks uid checks, which allows a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3883

Published Sep 11, 2016

internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not p…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3880

Published Sep 11, 2016

Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,176-5,200 of 5,607 CVEsPage 208 of 225