Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2016-3879

Published Sep 11, 2016

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows remote attackers to cause a deni…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3878

Published Sep 11, 2016

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause a denial of service (device h…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3863

Published Sep 11, 2016

Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x bef…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6179

Published Sep 7, 2016

The WiFi driver in Huawei Honor 6 smartphones with software H60-L01 before H60-L01C00B850, H60-L11 before H60-L11C00B850, H60-L21 before H60-L21C00B850, H60-L02 before H60-L02C00B…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7107

Published Sep 7, 2016

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently affect system data integrity via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6898

Published Sep 7, 2016

XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allows remote authenticated users…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6317

Published Sep 7, 2016

Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, w…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6184

Published Sep 7, 2016

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6183

Published Sep 7, 2016

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6182

Published Sep 7, 2016

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6181

Published Sep 7, 2016

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6180

Published Sep 7, 2016

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allo…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5383

Published Aug 26, 2016

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5673

Published Aug 25, 2016

UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5650

Published Aug 24, 2016

ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to trigger association with an arbitrary access point by using a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5645

Published Aug 24, 2016

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded SNMP community, which makes it…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2016-0760

Published Aug 19, 2016

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) reflect, (2) reflect2, or (3) ja…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2989

Published Aug 8, 2016

Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and co…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2960

Published Aug 8, 2016

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 5,201-5,225 of 5,607 CVEsPage 209 of 225