← Back
CWE-284

5,077 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,077)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apache
1Subversion
May 6, 2026
May 5, 2016
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended a...Show more
The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.Show less
1Linux
1Linux Kernel
May 6, 2026
May 2, 2016
N/A· v4
6.1 MEDIUM· v3
3.6 LOW· v2
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate...Show more
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locations beneath a mount by calling umount2 within a user namespace.Show less
1Linux
1Linux Kernel
May 6, 2026
May 2, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
1Mozilla
1Firefox
May 6, 2026
Apr 30, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences...Show more
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.Show less
1Mozilla
1Firefox
May 6, 2026
Apr 30, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.
1Lockon
1Ec Cube
May 6, 2026
Apr 30, 2016
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2016-1199.
3Linux
NovellSuse
8Linux Kernel
Suse Linux Enterprise DesktopSuse Linux Enterprise Live Patching+5 more
May 6, 2026
Apr 27, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows loc...Show more
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.Show less
1Wireshark
1Wireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop...Show more
epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.Show less
1Wireshark
1Wireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application cra...Show more
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
1Foxitsoftware
2Foxit Reader
Phantompdf
May 6, 2026
Apr 22, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
1Lemurmonitors
1Bluedriver
May 6, 2026
Apr 22, 2016
N/A· v4
8.8 HIGH· v3
8.0 HIGH· v2
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a devic...Show more
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or steering.Show less
8Apache
CanonicalDebian+5 more
38Cassandra
Debian LinuxE Series Santricity Management Plug Ins+35 more
Apr 22, 2026
Apr 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.Show less
3Google
OpensuseSuse
3Chrome
LeapLinux Enterprise
May 6, 2026
Apr 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a...Show more
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.Show less
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypa...Show more
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.Show less
1Sap
1Hana
May 6, 2026
Apr 14, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified o...Show more
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified other attacks via unspecified vectors, aka SAP Security Note 2262742.Show less
2Novell
Xen
2Suse Linux Enterprise Real Time Extension
Xen
May 6, 2026
Apr 14, 2016
N/A· v4
8.2 HIGH· v3
5.7 MEDIUM· v2
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a d...Show more
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.Show less
1Openstack
1Image Registry And Delivery Service (glance)
May 6, 2026
Apr 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by re...Show more
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.Show less
4Debian
FedoraprojectOracle+1 more
4Debian Linux
FedoraVm Server+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.Show less