CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 20 of 29
- CVE-2016-7583HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iCloud before 6.0.1 is affected. The issue involves the setup subsystem in the "iCloud" component. It allows local users to gain privileges via a crafted dynamic library in an unspecified …
- CVE-2016-7613HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attacker…
- CVE-2016-7628MEDIUMCVSS 5.5EG 5.52017-02-20
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Assets" component, which allows local users to bypass intended permission restrictions and change a downloaded mobile asset via un…
- CVE-2016-7660HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via uns…
- CVE-2016-7661HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related…
- CVE-2016-7786HIGHCVSS 8.8EG 8.82017-04-07
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.
- CVE-2016-7818HIGHCVSS 7.8EG 7.82017-06-09
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO …
- CVE-2016-7845MEDIUMCVSS 6.5EG 6.52017-08-02
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized file sharing.
- CVE-2016-7903LOWCVSS 3.7EG 3.72017-01-04
Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.
- CVE-2016-7942CRITICALCVSS 9.8EG 9.82016-12-13
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.
- CVE-2016-7944CRITICALCVSS 9.8EG 9.82016-12-13
Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.
- CVE-2016-7955CRITICALCVSS 9.8EG 9.82017-03-15
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the applica…
- CVE-2016-8005MEDIUMCVSS 6.5EG 6.52017-03-14
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a forged attached filename that uses a null b…
- CVE-2016-8006MEDIUMCVSS 4.4EG 4.42017-01-05
Authentication bypass vulnerability in Enterprise Security Manager (ESM) and License Manager (LM) in Intel Security McAfee Security Information and Event Management (SIEM) 9.6.0 MR3 allows an administrator to make changes to other SIEM use…
- CVE-2016-8008HIGHCVSS 8.8EG 8.82017-03-14
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.
- CVE-2016-8009HIGHCVSS 7.8EG 7.82017-03-14
Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code execution via an unauthorized use of IOCTL call.
- CVE-2016-8012HIGHCVSS 7.8EG 7.82017-03-14
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process…
- CVE-2016-8026HIGHCVSS 7.8EG 7.82017-03-14
Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.
- CVE-2016-8031HIGHCVSS 7.3EG 7.32017-03-28
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security protection via a crafted input file.
- CVE-2016-8101HIGHCVSS 7.8EG 7.82016-10-10
The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors.
- CVE-2016-8102HIGHCVSS 7.8EG 7.82016-12-08
Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges.
- CVE-2016-8103MEDIUMCVSS 6.7EG 6.72016-12-08
SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.
- CVE-2016-8202HIGHCVSS 8.8EG 8.82017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing…
- CVE-2016-8216MEDIUMCVSS 6.7EG 6.72017-02-03
EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior…
- CVE-2016-8221HIGHCVSS 7.0EG 7.02017-01-12
Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/output modules (IOMs), certain log files viewable by authenticated users may contain passwords…
- CVE-2016-8228HIGHCVSS 7.8EG 7.82017-06-04
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
- CVE-2016-8235HIGHCVSS 7.8EG 7.82017-04-10
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.
- CVE-2016-8237HIGHCVSS 8.1EG 8.12017-04-10
Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.
- CVE-2016-8289MEDIUMCVSS 4.7EG 4.72016-10-25
Unspecified vulnerability in Oracle MySQL 5.7.13 and earlier allows local users to affect integrity and availability via vectors related to Server: InnoDB.
- CVE-2016-8353MEDIUMCVSS 6.4EG 6.42017-02-13
An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the PI system without the proper permissions.
- CVE-2016-8357HIGHCVSS 7.1EG 7.12017-02-13
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only a…
- CVE-2016-8363CRITICALCVSS 10.0EG 10.02017-02-13
An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, WAC-1001 V2 Series, WAC-2004 Series, AWK-3121-M12-RTG Series, AWK-3131-M12-RCC Series, AWK-…
- CVE-2016-8417HIGHCVSS 7.0EG 7.02017-03-08
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromi…
- CVE-2016-8419HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8420HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8421HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8422HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-8423HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-8424HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8425HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8426HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8427HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8428HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8429HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8430HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8431HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8432HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local perma…
- CVE-2016-8433HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permane…
- CVE-2016-8436HIGHCVSS 7.8EG 7.82017-01-12
An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local p…
- CVE-2016-8445HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Hi…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →