Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,695 CVEs tagged with CWE-284719 Critical, 1,889 High, 2,551 Medium, 522 Low, 14 Unrated.

CVE-2015-4302

Published Aug 19, 2015

The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CS…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5512

Published Aug 18, 2015

The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5502

Published Aug 18, 2015

The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0277

Published Aug 17, 2015

The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attac…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-5746

Published Aug 17, 2015

AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3806

Published Aug 17, 2015

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3757

Published Aug 16, 2015

Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-3155

Published Aug 14, 2015

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3213

Published Aug 12, 2015

The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5960

Published Aug 8, 2015

Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB i…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-5623

Published Aug 3, 2015

WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leve…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3224

Published Jul 26, 2015

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2847

Published Jul 26, 2015

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removi…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1922

Published Jul 20, 2015

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4271

Published Jul 15, 2015

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv0060…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1763

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual function…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1761

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3007

Published Jul 14, 2015

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set sy…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1936

Published Jul 14, 2015

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1927

Published Jul 14, 2015

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webco…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1961

Published Jul 13, 2015

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows rem…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,551-5,575 of 5,695 CVEsPage 223 of 228