Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,612 CVEs tagged with CWE-284701 Critical, 1,857 High, 2,521 Medium, 519 Low, 14 Unrated.

CVE-2015-0531

Published May 7, 2015

EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a brute-for…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0914

Published May 1, 2015

EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1151

Published Apr 28, 2015

Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0297

Published Apr 24, 2015

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvoker…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0840

Published Apr 13, 2015

The dpkg-source command in Debian dpkg before 1.16.16 and 1.17.x before 1.17.25 allows remote attackers to bypass signature verification via a crafted Debian source control file (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0675

Published Apr 13, 2015

The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) does not properly validate fail…

CVSS 8.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1115

Published Apr 10, 2015

The Telephony component in Apple iOS before 8.3 allows attackers to bypass a sandbox protection mechanism and access unintended telephone capabilities via a crafted app.

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0119

Published Apr 6, 2015

FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mount port.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2841

Published Apr 3, 2015

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2816

Published Apr 1, 2015

The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 21…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2792

Published Mar 30, 2015

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce checks and perform arbitrary actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-2172

Published Mar 30, 2015

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users to gain privileges and add or d…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2559

Published Mar 25, 2015

Drupal 6.x before 6.35 and 7.x before 7.35 allows remote authenticated users to reset the password of other accounts by leveraging an account with the same password hash as anothe…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 5,526-5,550 of 5,612 CVEsPage 222 of 225