Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,806 CVEs tagged with CWE-284740 Critical, 1,944 High, 2,579 Medium, 530 Low, 13 Unrated.

CVE-2015-1922

Published Jul 20, 2015

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2015-4271

Published Jul 15, 2015

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request parameters, aka Bug ID CSCuv0060…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1763

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attempts to execute virtual function…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1761

Published Jul 14, 2015

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, which allows remote authentica…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3007

Published Jul 14, 2015

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not properly implement the "set sy…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1936

Published Jul 14, 2015

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disabled, allows remote authenticat…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1927

Published Jul 14, 2015

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false value for the com.ibm.ws.webco…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-1961

Published Jul 13, 2015

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 through 8.5.6.0 allows rem…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-4034

Published Jul 6, 2015

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitrary files via a crafted Parcela…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3692

Published Jul 3, 2015

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken from sleep, which allows local u…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-3691

Published Jul 3, 2015

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary code in a privileged context v…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-3675

Published Jul 3, 2015

The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attackers to bypass HTTP authenticat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3672

Published Jul 3, 2015

Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via unspecified vectors.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3671

Published Jul 3, 2015

Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain admin privileges via unspecifi…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2015-1959

Published Jun 28, 2015

IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not properly…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4418

Published Jun 9, 2015

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,676-5,700 of 5,806 CVEsPage 228 of 233