← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
2Elastic Storage Server
General Parallel File System Storage Server
May 6, 2026
Jun 19, 2016
N/A· v4
8.4 HIGH· v3
4.6 MEDIUM· v2
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows loc...Show more
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.Show less
1Netcommons
1Netcommons
May 6, 2026
Jun 19, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
1Microsoft
2Windows Server 2008
Windows Server 2012
May 6, 2026
Jun 16, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory...Show more
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."Show less
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
4Canonical
DebianLibndp+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+7 more
May 6, 2026
Jun 13, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of s...Show more
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.Show less
2Atheme
Opensuse
3Atheme
LeapOpensuse
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
1Citrix
1Xenserver
May 6, 2026
Jun 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Act...Show more
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.Show less
3Canonical
LibimobiledeviceOpensuse
5Leap
LibimobiledeviceLibusbmuxd+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP so...Show more
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.Show less
1Keystone
1Openstack Identity
May 6, 2026
Jun 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a t...Show more
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.Show less
1Bmc
1Bladelogic Server Automation Console
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sendin...Show more
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.Show less
4Canonical
DebianMozilla+1 more
5Debian Linux
FirefoxLeap+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduc...Show more
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.Show less
3Canonical
MozillaOpensuse
4Firefox
LeapOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation perm...Show more
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.Show less
3Canonical
MozillaOpensuse
4Firefox
LeapOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
4Canonical
DebianMozilla+1 more
5Debian Linux
FirefoxLeap+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
1Puppet
3Puppet
Puppet AgentPuppet Server
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decod...Show more
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.Show less
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
1Kmc Controls
1Bac 5051e Firmware
May 6, 2026
Jun 10, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.
4Debian
OpensuseRedhat+1 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
May 6, 2026
Jun 9, 2016
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
1Canonical
2Lxd
Ubuntu Linux
May 6, 2026
Jun 9, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
1Redhat
1Openshift
May 6, 2026
Jun 8, 2016
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network reso...Show more
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.Show less