CWE-284
5,077 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,077)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Siemens 18Primary Setup Tool Security Configuration ToolSimatic It Production Suite+15 moreMay 6, 2026 Nov 15, 2016 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (Al...Show more |
1Microsoft 5Windows 10 Windows 7Windows 8.1+2 moreMay 6, 2026 Nov 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted file, aka "Microsoft...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 6, 2026 Nov 10, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically proximate attackers to bypass the Secure Boot protection mechanism via a c...Show more |
Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Office Denial of Service Vulnerability." |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 6, 2026 Nov 10, 2016 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, a...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 6, 2026 Nov 10, 2016 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Eleva...Show more |
1Microsoft 2Windows 10 Windows Server 2016May 6, 2026 Nov 10, 2016 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Eleva...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 6, 2026 Nov 10, 2016 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local...Show more |
1Microsoft 5Windows 10 Windows 8.1Windows Rt 8.1+2 moreMay 6, 2026 Nov 10, 2016 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local...Show more |
1Microsoft 8Windows 10 Windows 7Windows 8.1+5 moreMay 6, 2026 Nov 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow remote attacker...Show more |
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE:...Show more |
2Debian Python2Debian Linux PillowMay 6, 2026 Nov 4, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component. |
Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits un...Show more |
1Ibm 1Financial Transaction Manager May 6, 2026 Oct 29, 2016 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp0015 and 3.0.1.0 before iFix0002 allows remote authenticated users to c...Show more |
1Alienvault 2Open Source Security Information And Event Management Unified Security ManagementMay 6, 2026 Oct 28, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes. |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 7.6 HIGH· v3 4.9 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to LD...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration...Show more |
1Oracle 1Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager May 6, 2026 Oct 25, 2016 N/A· v4 4.2 MEDIUM· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition M...Show more |
1Oracle 1Peoplesoft Enterprise Peopletools May 6, 2026 Oct 25, 2016 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Appli...Show more |
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect integrity via vectors related to Server: InnoDB Plugin. |