CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 10 of 126
- CVE-2016-4591HIGHCVSS 7.5EG 7.52016-07-22
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
- CVE-2016-4694CRITICALCVSS 9.1EG 9.12016-09-25
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable,…
- CVE-2016-4760MEDIUMCVSS 6.5EG 6.52016-09-25
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support.
- CVE-2016-4800CRITICALCVSS 9.8EG 9.82017-04-13
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped character…
- CVE-2016-4810HIGHCVSS 7.5EG 7.52016-06-01
Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors.
- CVE-2016-4811MEDIUMCVSS 5.6EG 5.62016-06-19
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
- CVE-2016-4813HIGHCVSS 8.8EG 8.82016-06-19
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
- CVE-2016-4850HIGHCVSS 8.1EG 8.12017-04-20
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
- CVE-2016-4874LOWCVSS 3.5EG 3.52017-04-17
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.
- CVE-2016-4908MEDIUMCVSS 4.3EG 4.32017-06-09
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
- CVE-2016-4910MEDIUMCVSS 4.3EG 4.32017-06-09
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
- CVE-2016-4911MEDIUMCVSS 4.3EG 4.32016-06-13
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
- CVE-2016-4963MEDIUMCVSS 4.7EG 4.72016-06-07
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.
- CVE-2016-4979HIGHCVSS 7.5EG 7.52016-07-06
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended ac…
- CVE-2016-5008CRITICALCVSS 9.8EG 9.82016-07-13
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.
- CVE-2016-5022CRITICALCVSS 9.8EG 9.82016-09-07
F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 1…
- CVE-2016-5023HIGHCVSS 7.5EG 7.52016-08-26
Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, when configured with a TCP profile, allow remote attackers to cause a denial of service (Tra…
- CVE-2016-5026MEDIUMCVSS 5.5EG 5.52017-01-30
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
- CVE-2016-5054HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
- CVE-2016-5058HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.
- CVE-2016-5101HIGHCVSS 8.8EG 8.82016-06-29
Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.
- CVE-2016-5104MEDIUMCVSS 5.3EG 5.32016-06-13
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
- CVE-2016-5109MEDIUMCVSS 4.3EG 4.32016-07-13
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application req…
- CVE-2016-5130MEDIUMCVSS 6.5EG 6.52016-07-23
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.
- CVE-2016-5144CRITICALCVSS 9.8EG 9.82016-08-07
The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass inten…
- CVE-2016-5173HIGHCVSS 7.1EG 7.12016-09-25
The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers to load unintended resources, and consequently trigger unintended JavaScript function calls…
- CVE-2016-5176MEDIUMCVSS 6.5EG 6.52016-09-29
Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
- CVE-2016-5189MEDIUMCVSS 6.5EG 6.52016-12-18
Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android permitted navigation to blob URLs with non-canonical origins, which allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via craf…
- CVE-2016-5192MEDIUMCVSS 6.5EG 6.52016-12-18
Blink in Google Chrome prior to 54.0.2840.59 for Windows missed a CORS check on redirect in TextTrackLoader, which allowed a remote attacker to bypass cross-origin restrictions via crafted HTML pages.
- CVE-2016-5206HIGHCVSS 8.8EG 8.82017-01-19
The PDF plugin in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly followed redirects, which allowed a remote attacker to bypass the Same Origin Policy via a crafted HTML page.
- CVE-2016-5217MEDIUMCVSS 6.5EG 6.52017-01-19
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly permitted access to privileged plugins, which allowed a remote attacker to bypass site isolation via a crafted H…
- CVE-2016-5229CRITICALCVSS 9.8EG 9.82016-08-02
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
- CVE-2016-5239CRITICALCVSS 9.8EG 9.82017-03-15
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2016-5273HIGHCVSS 8.8EG 8.82016-09-22
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.
- CVE-2016-5283HIGHCVSS 8.8EG 8.82016-09-22
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a docume…
- CVE-2016-5302CRITICALCVSS 9.8EG 9.82016-06-13
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory accou…
- CVE-2016-5341MEDIUMCVSS 5.9EG 5.92016-12-06
The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net…
- CVE-2016-5366HIGHCVSS 7.5EG 7.52016-06-14
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
- CVE-2016-5383HIGHCVSS 8.8EG 8.82016-08-26
The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."
- CVE-2016-5386HIGHCVSS 8.1EG 8.12016-07-19
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variabl…
- CVE-2016-5388HIGHCVSS 8.1EG 8.42016-07-19
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment v…
- CVE-2016-5393HIGHCVSS 8.8EG 8.82016-11-29
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
- CVE-2016-5404MEDIUMCVSS 6.5EG 6.52016-09-07
The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission.
- CVE-2016-5414HIGHCVSS 7.5EG 7.52017-06-27
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
- CVE-2016-5482HIGHCVSS 8.2EG 8.22016-10-25
Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
- CVE-2016-5491HIGHCVSS 8.2EG 8.22016-10-25
Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect confidentiality and integrity via unknown vectors.
- CVE-2016-5492HIGHCVSS 7.1EG 7.12016-10-25
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affect confidentiality and integrity via vectors related to SMB Users.
- CVE-2016-5493MEDIUMCVSS 4.2EG 4.22016-10-25
Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
- CVE-2016-5495HIGHCVSS 7.5EG 7.52016-10-25
Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality via vectors related to EUL Code & Schema.
- CVE-2016-5497MEDIUMCVSS 6.4EG 6.42016-10-25
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →