Skip to main content

CWE archive

CWE-284 CVEs

Programmatic archive

5,809 CVEs tagged with CWE-284740 Critical, 1,945 High, 2,581 Medium, 530 Low, 13 Unrated.

CVE-2014-8680

Published Dec 11, 2014

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via vectors related to (1) the la…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-6319

Published Dec 11, 2014

Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9117

Published Dec 6, 2014

MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-9151

Published Dec 1, 2014

The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6627

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6626

Published Nov 19, 2014

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass aut…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6625

Published Nov 19, 2014

The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-7905

Published Nov 19, 2014

Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to b…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-6110

Published Nov 18, 2014

IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workst…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-0228

Published Nov 16, 2014

Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remo…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2014-3120

Published Jul 28, 2014

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source p…

CVSS 8.1 · High
evidence mentions
8
Buzz score
61.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2014-2365

Published Jul 19, 2014

Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7293

Published Jan 15, 2014

The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to instead access a DNS hostname tha…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6068

Published Jan 21, 2013

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-5076

Published Oct 16, 2012

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, an…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
50.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 5,776-5,800 of 5,809 CVEsPage 232 of 233