Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

6,304 CVEs tagged with CWE-284798 Critical, 2,216 High, 2,728 Medium, 560 Low, 2 Unrated.

CVE-2016-6776

Published Jan 12, 2017

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6775

Published Jan 12, 2017

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6771

Published Jan 12, 2017

An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functions beyond its access level. This issue is rated as Moderate…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6770

Published Jan 12, 2017

An elevation of privilege vulnerability in the Framework API could enable a local malicious application to access system functions beyond its access level. This issue is rated as…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-6769

Published Jan 12, 2017

An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it f…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6768

Published Jan 12, 2017

A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivile…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6763

Published Jan 12, 2017

A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted file to cause a device hang or reboot. This issue is rated as…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6761

Published Jan 12, 2017

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. T…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6760

Published Jan 12, 2017

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. T…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6759

Published Jan 12, 2017

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. T…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6758

Published Jan 12, 2017

An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. T…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6755

Published Jan 12, 2017

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This i…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2015-4594

Published Jan 10, 2017

eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it poss…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10124

Published Jan 9, 2017

An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIO…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4307

Published Jan 6, 2017

A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violat…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4305

Published Jan 6, 2017

A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially crafted native api call can cause a access…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4304

Published Jan 6, 2017

A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A specially crafted native api call request can cau…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10030

Published Jan 5, 2017

The _prolog_error function in slurmd/req.c in Slurm before 15.08.13, 16.x before 16.05.7, and 17.x before 17.02.0-pre4 has a vulnerability in how the slurmd daemon informs users o…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10105

Published Jan 3, 2017

admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it con…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-10085

Published Dec 30, 2016

admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10084

Published Dec 30, 2016

admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10082

Published Dec 30, 2016

include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-7967

Published Dec 23, 2016

KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5192

Published Dec 18, 2016

Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions vi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,701-5,725 of 6,304 CVEsPage 229 of 253