CWE-284
5,470 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,470)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1F5 13Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+10 moreMay 6, 2026 Apr 12, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Incomplete blacklist vulnerability in the Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, Link Controller, and PSM 11.x before 11.2.1 HF11, 11.3.x, 11.4.0 before HF8, and 11.4.1 before HF6; BIG-IP AAM 1...Show more |
1Trendmicro 1Password Manager May 6, 2026 Apr 12, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB. |
1Pulsesecure 1Pulse Connect Secure May 6, 2026 Apr 12, 2016 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspec...Show more |
1Mcafee 7Active Response AgentData Exchange Layer+4 moreMay 6, 2026 Apr 8, 2016 N/A· v4 5.1 MEDIUM· v3 3.6 LOW· v2 The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B...Show more |
1Huawei 3Mate S Firmware P8P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before...Show more |
1Huawei 2Mate S Firmware P8 FirmwareMay 6, 2026 Apr 7, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C...Show more |
1Rockwellautomation 1Integrated Architecture Builder May 6, 2026 Apr 6, 2016 N/A· v4 6.3 MEDIUM· v3 6.9 MEDIUM· v2 IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file. |
1Eaton Lighting Systems 1Eg2 Web Control May 6, 2026 Apr 6, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie. |
shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified ve...Show more |
1Ibm 1Tivoli Storage Manager Fastback May 6, 2026 Apr 5, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port. |
The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app. |
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges...Show more |
WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a crafted web site. |
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request. |
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in oppo...Show more |
The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL. |
1Ibm 8Maximo Asset Management Maximo For GovernmentMaximo For Life Sciences+5 moreMay 6, 2026 Mar 14, 2016 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors. |
IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to cause a denial of service (order-processing outage) via unspecified vectors. |