Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,695 CVEs tagged with CWE-284719 Critical, 1,889 High, 2,551 Medium, 522 Low, 14 Unrated.

CVE-2015-4034

Published Jul 6, 2015

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcela…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3692

Published Jul 3, 2015

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local u…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3691

Published Jul 3, 2015

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context v…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3675

Published Jul 3, 2015

The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authenticat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3672

Published Jul 3, 2015

Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3671

Published Jul 3, 2015

Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecifi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1959

Published Jun 28, 2015

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4418

Published Jun 9, 2015

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-2959

Published Jun 9, 2015

Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive information, modify passwords, or…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4051

Published Jun 8, 2015

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), cre…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-4050

Published Jun 2, 2015

FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-2267

Published Jun 1, 2015

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and ex…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1937

Published May 30, 2015

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-0755

Published May 29, 2015

The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to gain privileges via unspecifi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0180

Published May 25, 2015

The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions on job creation and modificati…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1253

Published May 20, 2015

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers to bypass the Same Origin Polic…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 5,576-5,600 of 5,695 CVEsPage 224 of 228