Skip to main content

CWE archive

CWE-863 CVEs

Programmatic archive

3,536 CVEs tagged with CWE-863345 Critical, 1,229 High, 1,694 Medium, 265 Low, 3 Unrated.

CVE-2017-2305

Published May 30, 2017

On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrative web interface can create pri…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7505

Published May 26, 2017

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to some organization(s) can do all…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-0894

Published May 8, 2017

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3817

Published Apr 7, 2017

A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthoriz…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0881

Published Mar 28, 2017

An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat application server before 1.4.3 allowed an authenticated user t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5618

Published Mar 20, 2017

GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6377

Published Mar 16, 2017

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resulting in an access bypass.

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2017-6590

Published Mar 9, 2017

An issue was discovered in network-manager-applet (aka network-manager-gnome) in Ubuntu 12.04 LTS, 14.04 LTS, 16.04 LTS, and 16.10. A local attacker could use this issue at the de…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3520

Published Oct 26, 2014

OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to an unauthorized project for wh…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6926

Published Dec 17, 2013

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1342

Published Aug 6, 2012

Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1207

Published May 5, 2011

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect 11.4.0.2, 11.4.0.1, and earli…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-1123

Published Mar 1, 2011

Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-7109

Published Aug 28, 2009

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to the client system via a modified…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 3,501-3,525 of 3,536 CVEsPage 141 of 142