Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,607 CVEs tagged with CWE-284701 Critical, 1,856 High, 2,521 Medium, 519 Low, 10 Unrated.

CVE-2015-4418

Published Jun 9, 2015

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2959

Published Jun 9, 2015

Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4051

Published Jun 8, 2015

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), cre…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-4050

Published Jun 2, 2015

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2267

Published Jun 1, 2015

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and ex…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1937

Published May 30, 2015

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0755

Published May 29, 2015

The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecifi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0180

Published May 25, 2015

The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modificati…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1253

Published May 20, 2015

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Polic…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1920

Published May 20, 2015

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers to execute arbitrary code by…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3306

Published May 18, 2015

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2015-3644

Published May 14, 2015

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,501-5,525 of 5,607 CVEsPage 221 of 225