CWE-284
5,470 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,470)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop...Show more |
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application cra...Show more |
1Foxitsoftware 2Foxit Reader PhantompdfMay 6, 2026 Apr 22, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call. |
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a devic...Show more |
8Apache CanonicalDebian+5 more38Cassandra Debian LinuxE Series Santricity Management Plug Ins+35 moreApr 22, 2026 Apr 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |
4Debian GoogleNovell+1 more4Chrome Debian LinuxLeap+1 moreMay 6, 2026 Apr 18, 2016 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more |
3Google OpensuseSuse3Chrome LeapLinux EnterpriseMay 6, 2026 Apr 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors. |
2Canonical Redhat2Libvirt Ubuntu LinuxMay 6, 2026 Apr 14, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a...Show more |
2Canonical Redhat2Libvirt Ubuntu LinuxMay 6, 2026 Apr 14, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypa...Show more |
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified o...Show more |
2Novell Xen2Suse Linux Enterprise Real Time Extension XenMay 6, 2026 Apr 14, 2016 N/A· v4 8.2 HIGH· v3 5.7 MEDIUM· v2 Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a d...Show more |
1Openstack 1Image Registry And Delivery Service (glance) May 6, 2026 Apr 13, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by re...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraVm Server+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more |
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more |
4Canonical Git ProjectOpensuse+1 more4Git OpensuseSoftware Collections+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more |
1Microsoft 6Windows 7 Windows 8.1Windows Rt 8.1+3 moreMay 6, 2026 Apr 12, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file...Show more |
1Microsoft 3Windows 10 Windows 8.1Windows Server 2012May 6, 2026 Apr 12, 2016 N/A· v4 9.3 CRITICAL· v3 7.2 HIGH· v2 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability...Show more |
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that...Show more |
2Debian Drupal2Debian Linux DrupalMay 6, 2026 Apr 12, 2016 N/A· v4 8.1 HIGH· v3 6.5 MEDIUM· v2 The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more |
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream. |