CWE-284
5,077 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,077)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more |
4Canonical Git ProjectOpensuse+1 more4Git OpensuseSoftware Collections+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more |
1Microsoft 6Windows 7 Windows 8.1Windows Rt 8.1+3 moreMay 6, 2026 Apr 12, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file...Show more |
1Microsoft 3Windows 10 Windows 8.1Windows Server 2012May 6, 2026 Apr 12, 2016 N/A· v4 9.3 CRITICAL· v3 7.2 HIGH· v2 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability...Show more |
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more |
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream. |
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreMay 6, 2026 Apr 12, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 1...Show more |
1Trendmicro 1Password Manager May 6, 2026 Apr 12, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. |
1Pulsesecure 1Pulse Connect Secure May 6, 2026 Apr 12, 2016 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspec...Show more |
1Mcafee 7Active Response AgentData Exchange Layer+4 moreMay 6, 2026 Apr 8, 2016 N/A· v4 5.1 MEDIUM· v3 3.6 LOW· v2 The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B...Show more |
1Huawei 3Mate S Firmware P8P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C...Show more |
1Rockwellautomation 1Integrated Architecture Builder May 6, 2026 Apr 6, 2016 N/A· v4 6.3 MEDIUM· v3 6.9 MEDIUM· v2 IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file. |
1Eaton Lighting Systems 1Eg2 Web Control May 6, 2026 Apr 6, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie. |
shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified ve...Show more |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port. |
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app. |