← Back
CWE-284

5,077 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,077)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Citrix
2Worx Home
Xenmobile Mdx Toolkit
May 6, 2026
Jul 13, 2016
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to...Show more
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.Show less
2Debian
Redhat
2Debian Linux
Libvirt
May 6, 2026
Jul 13, 2016
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to...Show more
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 6, 2026
Jul 13, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScrip...Show more
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
1Microsoft
2Edge
Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."
1Microsoft
1Edge
May 6, 2026
Jul 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge Security Feature Bypass."
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28740702.
1Google
1Android
May 6, 2026
Jul 11, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a deni...Show more
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS outage) via a crafted application, aka Android internal bug 28821448 and Qualcomm internal bug CR681965.Show less
1Ibm
1Jazz Reporting Service
May 6, 2026
Jul 8, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote aut...Show more
The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 maintain session ID validity after a logout action, which allows remote authenticated users to hijack sessions by leveraging an unattended workstation.Show less
1Apache
1Http Server
May 6, 2026
Jul 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to...Show more
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restrictions by leveraging the ability to send multiple requests over a single connection and aborting a renegotiation.Show less
1Emc
1Avamar
May 6, 2026
Jul 6, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup...Show more
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.Show less
1Ibm
1Watson Developer Cloud
May 6, 2026
Jul 2, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechani...Show more
The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.Show less
1Symantec
1Endpoint Protection Manager
May 6, 2026
Jun 30, 2016
N/A· v4
2.9 LOW· v3
3.3 LOW· v2
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device man...Show more
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a new USB device.Show less
1Ibm
1Business Process Manager
May 6, 2026
Jun 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.
1Opera
1Opera Mail
May 6, 2026
Jun 29, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.
1Linux
1Linux Kernel
May 6, 2026
Jun 29, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.c, nfs3acl.c, and nfs4acl.c.
1Ibm
1Domino
May 6, 2026
Jun 29, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and po...Show more
The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.Show less
1Linux
1Linux Kernel
May 6, 2026
Jun 27, 2016
N/A· v4
7.1 HIGH· v3
5.6 MEDIUM· v2
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive...Show more
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.Show less
3Linux
NovellRedhat
4Enterprise Linux For Real Time
Enterprise Linux For Real Time For NfvLinux Kernel Rt+1 more
May 6, 2026
Jun 27, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other p...Show more
The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.Show less