← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wireshark
1Wireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop...Show more
epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.Show less
1Wireshark
1Wireshark
May 6, 2026
Apr 25, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application cra...Show more
epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.Show less
1Foxitsoftware
2Foxit Reader
Phantompdf
May 6, 2026
Apr 22, 2016
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.
1Lemurmonitors
1Bluedriver
May 6, 2026
Apr 22, 2016
N/A· v4
8.8 HIGH· v3
8.0 HIGH· v2
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a devic...Show more
The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or steering.Show less
8Apache
CanonicalDebian+5 more
38Cassandra
Debian LinuxE Series Santricity Management Plug Ins+35 more
Apr 22, 2026
Apr 21, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
4Debian
GoogleNovell+1 more
4Chrome
Debian LinuxLeap+1 more
May 6, 2026
Apr 18, 2016
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive infor...Show more
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.Show less
3Google
OpensuseSuse
3Chrome
LeapLinux Enterprise
May 6, 2026
Apr 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unspecified vectors.
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a...Show more
The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of service (libvirtd crash) by triggering a failed unlink after creating a volume on a root_squash NFS pool.Show less
2Canonical
Redhat
2Libvirt
Ubuntu Linux
May 6, 2026
Apr 14, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypa...Show more
The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks when libvirtd is restarted, which might allow remote attackers to bypass intended access restrictions via a (1) DNS or (2) DHCP query.Show less
1Sap
1Hana
May 6, 2026
Apr 14, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified o...Show more
The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to obtain sensitive information, gain privileges, and conduct unspecified other attacks via unspecified vectors, aka SAP Security Note 2262742.Show less
2Novell
Xen
2Suse Linux Enterprise Real Time Extension
Xen
May 6, 2026
Apr 14, 2016
N/A· v4
8.2 HIGH· v3
5.7 MEDIUM· v2
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a d...Show more
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.Show less
1Openstack
1Image Registry And Delivery Service (glance)
May 6, 2026
Apr 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by re...Show more
OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.Show less
4Debian
FedoraprojectOracle+1 more
4Debian Linux
FedoraVm Server+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.Show less
3Fedoraproject
OracleXen
3Fedora
Vm ServerXen
May 6, 2026
Apr 13, 2016
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.Show less
4Canonical
Git ProjectOpensuse+1 more
4Git
OpensuseSoftware Collections+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might al...Show more
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.Show less
1Microsoft
6Windows 7
Windows 8.1Windows Rt 8.1+3 more
May 6, 2026
Apr 12, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file...Show more
OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Remote Code Execution Vulnerability."Show less
1Microsoft
3Windows 10
Windows 8.1Windows Server 2012
May 6, 2026
Apr 12, 2016
N/A· v4
9.3 CRITICAL· v3
7.2 HIGH· v2
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability...Show more
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability."Show less
1Drupal
1Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that...Show more
The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.Show less
2Debian
Drupal
2Debian Linux
Drupal
May 6, 2026
Apr 12, 2016
N/A· v4
8.1 HIGH· v3
6.5 MEDIUM· v2
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveragin...Show more
The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.Show less
2Opensuse
Saltstack
2Leap
Salt
May 6, 2026
Apr 12, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.