CWE-284
5,080 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,080)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian MozillaRedhat6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreNov 25, 2025 Jun 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6. |
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2....Show more |
Improper access control vulnerability in Synology Drive before 1.0.2-10275 allows remote authenticated users to access non-shared files or folders via unspecified vectors. |
Sails is an MVC style framework for building realtime web applications. Version 0.12.7 and lower have an issue with the CORS configuration where the value of the origin header is reflected as the value for the Access-Con...Show more |
Hapi versions less than 11.0.0 implement CORS incorrectly and allowed for configurations that at best returned inconsistent headers and at worst allowed cross-origin activities that were expected to be forbidden. If the...Show more |
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config tha...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 May 22, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation. |
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allo...Show more |
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com sit...Show more |
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary number...Show more |
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855. |
1Ibm 1Integrated Management Module Firmware Nov 21, 2024 Apr 25, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an...Show more |
2Openstack Redhat2Openstack Puppet TripleoNov 21, 2024 Apr 24, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the IPtables rules management, which allowed the creation of TCP/UDP rules with empty port values. If SSL is enabled, a malicious use...Show more |
1Ibm 2Security Identity Manager Tivoli Identity ManagerNov 21, 2024 Apr 20, 2018 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intend...Show more |
1Qualcomm 27Mdm9206 Firmware Mdm9607 FirmwareMdm9650 Firmware+24 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600,...Show more |
1Qualcomm 23Sd 410 Firmware Sd 412 FirmwareSd 415 Firmware+20 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 808, SD 810,...Show more |
1Qualcomm 11Mdm9206 Firmware Sd 205 FirmwareSd 210 Firmware+8 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 820A, and S...Show more |
1Qualcomm 7Mdm9640 Firmware Mdm9650 FirmwareMsm8937 Firmware+4 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9640, SDM630, MSM8976, MSM8937, SDM845, MSM8976, and MSM8952, when running module or kernel code with improper access control...Show more |
1Qualcomm 6Sd 425 Firmware Sd 430 FirmwareSd 450 Firmware+3 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, and SD 650/52, there is improper access control to a bus. |
1Qualcomm 30Fsm9055 Firmware Ipq4019 FirmwareMdm9206 Firmware+27 moreNov 21, 2024 Apr 18, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear FSM9055, IPQ4019, MDM9206, MDM9635M, MDM9640, MDM9645, MDM9650, MDM96...Show more |