CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
6,247 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 6 of 125
- CVE-2016-10084HIGHCVSS 7.2EG 7.22016-12-30
admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).
- CVE-2016-10085HIGHCVSS 7.2EG 7.22016-12-30
admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.
- CVE-2016-10105CRITICALCVSS 9.8EG 9.82017-01-03
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence.
- CVE-2016-10124HIGHCVSS 8.6EG 8.62017-01-09
An issue was discovered in Linux Containers (LXC) before 2016-02-22. When executing a program via lxc-attach, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buff…
- CVE-2016-10130MEDIUMCVSS 5.9EG 5.92017-03-24
The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.
- CVE-2016-10144CRITICALCVSS 9.8EG 9.82017-03-24
coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.
- CVE-2016-10148MEDIUMCVSS 4.3EG 4.32017-01-18
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-ac…
- CVE-2016-10193CRITICALCVSS 9.8EG 9.82017-03-03
The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, save, bytes or bytes_wav method in lib/espeak/speech.rb.
- CVE-2016-10223MEDIUMCVSS 5.4EG 5.42017-02-14
An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP GET parameter passed to the "core/admin/adjax/dashboard/check-module-integrity.php" URL. A…
- CVE-2016-10237HIGHCVSS 7.8EG 7.82017-05-16
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated …
- CVE-2016-10333MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
- CVE-2016-10334MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
- CVE-2016-10335MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
- CVE-2016-10369HIGHCVSS 7.8EG 7.82017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).
- CVE-2016-10370HIGHCVSS 7.5EG 7.52017-05-11
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessari…
- CVE-2016-1038CRITICALCVSS 10.0EG 10.02016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10382CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.
- CVE-2016-1039CRITICALCVSS 9.8EG 9.82016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-1040CRITICALCVSS 9.8EG 9.82016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10408HIGHCVSS 8.4EG 8.42024-11-26
QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. Device memory is not valid executable memory.
- CVE-2016-1041CRITICALCVSS 10.0EG 10.02016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10417HIGHCVSS 8.1EG 8.12018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 21…
- CVE-2016-10418HIGHCVSS 7.5EG 7.52018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, and …
- CVE-2016-1042CRITICALCVSS 9.8EG 9.82016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10422CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, MDM9206, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, SD 210/SD 212/S…
- CVE-2016-1044CRITICALCVSS 10.0EG 10.02016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10440CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, and SD 650/52, there is improper access control to a bus.
- CVE-2016-10442CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control allowing writing to…
- CVE-2016-10444CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, and SD 835, SMMU Access …
- CVE-2016-10462CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, S…
- CVE-2016-10472CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, …
- CVE-2016-10514MEDIUMCVSS 6.5EG 6.52017-10-10
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:…
- CVE-2016-10549MEDIUMCVSS 4.4EG 4.42018-05-31
Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Control-Allow-Origin h…
- CVE-2016-1062CRITICALCVSS 9.8EG 9.82016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-10792HIGHCVSS 8.8EG 8.82019-08-06
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
- CVE-2016-10799MEDIUMCVSS 5.5EG 5.52019-08-07
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
- CVE-2016-10802HIGHCVSS 8.8EG 8.82019-08-07
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
- CVE-2016-10820HIGHCVSS 8.8EG 8.82019-08-01
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31).
- CVE-2016-10830HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
- CVE-2016-10838MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
- CVE-2016-10852MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
- CVE-2016-10856MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
- CVE-2016-10857MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
- CVE-2016-10860HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
- CVE-2016-1117CRITICALCVSS 9.8EG 9.82016-05-11
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-1178MEDIUMCVSS 6.5EG 6.52017-04-12
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
- CVE-2016-1190MEDIUMCVSS 6.5EG 6.52016-06-25
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.
- CVE-2016-1200MEDIUMCVSS 6.3EG 6.32016-04-30
The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2016-1199.
- CVE-2016-1220MEDIUMCVSS 4.3EG 4.32017-04-20
Cybozu Garoon before 4.2.2 does not properly restrict access.
- CVE-2016-1237MEDIUMCVSS 5.5EG 5.52016-06-29
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →