← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Janitza
5Umg 508
Umg 509Umg 511+2 more
May 6, 2026
Oct 28, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or write to files, or execute arbitrary JASIC code, via a session on TCP port...Show more
The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or write to files, or execute arbitrary JASIC code, via a session on TCP port 1239.Show less
1Colorbox Project
1Colorbox
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors,...Show more
The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 23, 2015
N/A· v4
N/A· v3
8.8 HIGH· v2
libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.
4Opensuse
OracleRedhat+1 more
21Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Eus Compute Node+18 more
Apr 22, 2026
Oct 22, 2015
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
1Mozilla
1Firefox
May 6, 2026
Oct 18, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is im...Show more
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Revive Adserver
1Revive Adserver
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.
1Revive Adserver
1Revive Adserver
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.
1Google
1Chrome
May 6, 2026
Oct 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) o...Show more
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.
1Ibm
1Openpages Grc Platform
May 6, 2026
Oct 3, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request.
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate atta...Show more
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access restrictions via a long password that triggers a SystemUI crash, aka internal bug 22214934.Show less
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the...Show more
The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.Show less
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application...Show more
The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.Show less
1Cubecart
1Cubecart
May 6, 2026
Sep 28, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a r...Show more
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.Show less
1Drupaldise
1Cms Updater
May 6, 2026
Sep 21, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" p...Show more
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.Show less
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted app.
1Apple
2Iphone Os
Safari
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Poli...Show more
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Unit4
1Teta Web
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted "received...Show more
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted "received parameters."Show less