CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,274 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 16 of 126
- CVE-2016-8821HIGHCVSS 7.8EG 7.82016-12-16
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where improper access controls may allow a user to access arbitrary physical memory, leading to an escalation of pr…
- CVE-2016-8824HIGHCVSS 7.8EG 7.82016-12-16
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where improper access controls allow a regular user to write a part of the registry intended for pri…
- CVE-2016-8915MEDIUMCVSS 6.5EG 6.52017-02-22
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under the same process. IBM Reference #: 1998649.
- CVE-2016-8931HIGHCVSS 8.8EG 8.82017-02-01
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
- CVE-2016-8932HIGHCVSS 8.8EG 8.82017-02-01
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
- CVE-2016-8938CRITICALCVSS 10.0EG 10.02017-02-01
IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on the server. This code could be executed on the UCD agent machines that host customer's production applications.
- CVE-2016-8942LOWCVSS 3.1EG 3.12017-02-01
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.
- CVE-2016-8986MEDIUMCVSS 6.5EG 6.52017-02-22
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP requests. IBM Reference #: 1998648.
- CVE-2016-9005CRITICALCVSS 9.8EG 9.82017-02-08
IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and gain remote access to the system.
- CVE-2016-9008HIGHCVSS 7.5EG 7.52017-02-01
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
- CVE-2016-9016HIGHCVSS 8.8EG 8.82017-01-19
Firejail 0.9.38.4 allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
- CVE-2016-9111MEDIUMCVSS 6.8EG 6.82016-11-07
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the…
- CVE-2016-9122HIGHCVSS 7.5EG 7.52017-03-28
go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could p…
- CVE-2016-9155CRITICALCVSS 9.8EG 9.82016-11-22
The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1.73_S1; CCMD3025-DN18 prior to version v1.394_S1; CCID1445-DN18, CCID1445-DN28, CCID1145-D…
- CVE-2016-9156HIGHCVSS 7.3EG 7.32016-12-05
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.
- CVE-2016-9157CRITICALCVSS 9.8EG 9.82016-12-05
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to por…
- CVE-2016-9182HIGHCVSS 7.5EG 7.52016-11-04
Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits undefined actions to …
- CVE-2016-9190HIGHCVSS 7.8EG 7.82016-11-04
Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.
- CVE-2016-9245MEDIUMCVSS 5.9EG 5.92017-03-07
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is exposed with BIG-IP APM profiles, regardless of settings. The issue is also exposed with the n…
- CVE-2016-9356HIGHCVSS 7.8EG 7.82017-02-13
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.
- CVE-2016-9368HIGHCVSS 7.5EG 7.52017-03-14
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authent…
- CVE-2016-9378MEDIUMCVSS 5.5EG 5.52017-02-22
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice fo…
- CVE-2016-9412CRITICALCVSS 9.8EG 9.82017-01-31
MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allow attackers to have unspecified impact via vectors related to low adminsid and sid entropy.
- CVE-2016-9413MEDIUMCVSS 6.5EG 6.52017-01-31
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
- CVE-2016-9415HIGHCVSS 7.5EG 7.52017-01-31
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers to overwrite arbitrary CSS files via vectors related to "style import."
- CVE-2016-9460MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link …
- CVE-2016-9461MEDIUMCVSS 4.3EG 4.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an a…
- CVE-2016-9462MEDIUMCVSS 4.3EG 4.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a…
- CVE-2016-9467MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid…
- CVE-2016-9468MEDIUMCVSS 5.3EG 5.32017-03-28
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a p…
- CVE-2016-9565CRITICALCVSS 9.8EG 9.82016-12-15
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists bec…
- CVE-2016-9599HIGHCVSS 7.1EG 7.52018-04-24
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious user could use these o…
- CVE-2016-9639CRITICALCVSS 9.1EG 9.12017-02-07
Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching.
- CVE-2016-9645MEDIUMCVSS 6.5EG 6.52018-04-10
The fix for ikiwiki for CVE-2016-10026 was incomplete resulting in editing restriction bypass for git revert when using git versions older than 2.8.0. This has been fixed in 3.20161229.
- CVE-2016-9722MEDIUMCVSS 4.2EG 4.22018-01-10
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.
- CVE-2016-9815MEDIUMCVSS 6.5EG 6.52017-02-27
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort.
- CVE-2016-9816MEDIUMCVSS 6.5EG 6.52017-02-27
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2.
- CVE-2016-9817MEDIUMCVSS 6.5EG 6.52017-02-27
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort with the ESR_EL2.EA bit set.
- CVE-2016-9818MEDIUMCVSS 6.5EG 6.52017-02-27
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP.
- CVE-2016-9835CRITICALCVSS 9.8EG 9.82016-12-05
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
- CVE-2016-9836CRITICALCVSS 9.8EG 9.82016-12-05
The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the…
- CVE-2016-9838HIGHCVSS 7.5EG 7.52016-12-16
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's…
- CVE-2016-9877CRITICALCVSS 9.8EG 9.82016-12-29
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, and 1.7.x before 1.7.7. MQTT (MQ Telemetry Transport) connection authentication with a usern…
- CVE-2016-9905HIGHCVSS 8.8EG 8.82018-06-11
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
- CVE-2016-9920HIGHCVSS 7.5EG 7.52016-12-08
steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command l…
- CVE-2016-9951MEDIUMCVSS 6.5EG 6.52016-12-17
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prom…
- CVE-2016-9956HIGHCVSS 7.5EG 7.52017-02-22
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
- CVE-2016-9976HIGHCVSS 8.4EG 8.42017-05-03
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL request, which could allow the attacker to execute arbitrary code on the vulnerabl…
- CVE-2017-10721MEDIUMCVSS 6.5EG 6.52019-06-17
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users…
- CVE-2017-11365CRITICALCVSS 9.8EG 9.82019-05-23
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →