← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Bamboo
May 6, 2026
Aug 2, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.
1Hp
1Operations Manager
May 6, 2026
Aug 1, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections...Show more
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.Show less
1Novell
1Filr
May 6, 2026
Aug 1, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.
3Cronic Project
DebianOpensuse
4Cronic
Debian LinuxLeap+1 more
May 6, 2026
Jul 26, 2016
N/A· v4
6.2 MEDIUM· v3
4.9 MEDIUM· v2
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
1Google
1Chrome
May 6, 2026
Jul 23, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted we...Show more
content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.Show less
1Apple
1Webkit
May 6, 2026
Jul 22, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.
4Apache
HpOracle+1 more
11Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+8 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_...Show more
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.Show less
4Fedoraproject
GolangOracle+1 more
6Enterprise Linux Server
Enterprise Linux Server AusEnterprise Linux Server Eus+3 more
May 6, 2026
Jul 19, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY...Show more
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.Show less
1Accela
1Civic Platform Citizen Access Portal
May 6, 2026
Jul 15, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters.
1Ibm
1Security Identity Manager Adapter
May 6, 2026
Jul 15, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote attackers to conduct clickjacking attacks via a crafted web site.
1Ibm
1Security Identity Manager Adapter
May 6, 2026
Jul 15, 2016
N/A· v4
7.4 HIGH· v3
4.4 MEDIUM· v2
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended works...Show more
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allows remote attackers to hijack sessions by leveraging an unattended workstation.Show less
1Ibm
1Security Identity Manager Adapter
May 6, 2026
Jul 15, 2016
N/A· v4
5.6 MEDIUM· v3
4.3 MEDIUM· v2
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leverag...Show more
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logout, which makes it easier for remote attackers to spoof users by leveraging knowledge of "traffic records."Show less
1Tollgrade
1Lighthouse Sms
May 6, 2026
Jul 15, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
1Citrix
2Worx Home
Xenmobile Mdx Toolkit
May 6, 2026
Jul 13, 2016
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to...Show more
Citrix Worx Home for iOS before 10.3.6 and XenMobile MDX Toolkit for iOS before 10.3.6 might allow physically proximate attackers to bypass in-application Apple Touch ID authentication via unspecified vectors, related to an application requiring re-authentication.Show less
2Debian
Redhat
2Debian Linux
Libvirt
May 6, 2026
Jul 13, 2016
N/A· v4
9.8 CRITICAL· v3
4.3 MEDIUM· v2
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to...Show more
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.Show less
1Adobe
4Acrobat
Acrobat DcAcrobat Reader Dc+1 more
May 6, 2026
Jul 13, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScrip...Show more
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors.Show less
1Microsoft
1Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
1Microsoft
2Edge
Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
3.1 LOW· v3
2.6 LOW· v2
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
1Microsoft
1Internet Explorer
May 6, 2026
Jul 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Internet Explorer 9 through 11 allows remote attackers to trick users into making TCP connections to a restricted port via a crafted web site, aka "Internet Explorer Security Feature Bypass Vulnerability."
1Microsoft
1Edge
May 6, 2026
Jul 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge Security Feature Bypass."