← Back
CWE-284

5,470 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,470)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Ruggedcom Rugged Operating System
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.
1Microsoft
3Windows 10
Windows 8.1Windows Server 2012
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V...Show more
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability."Show less
1Microsoft
4Windows 7
Windows 8Windows 8.1+1 more
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Medi...Show more
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."Show less
1Cisco
1Unified Web And E Mail Interaction Manager
May 6, 2026
Aug 19, 2015
N/A· v4
N/A· v3
5.5 MEDIUM· v2
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCu...Show more
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default messaging-queue system folders via unspecified vectors, aka Bug ID CSCuo89046.Show less
1Cisco
1Unified Web And E Mail Interaction Manager
May 6, 2026
Aug 19, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo8905...Show more
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.Show less
1Cisco
1Firesight System Software
May 6, 2026
Aug 19, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.
1Me Aliases Project
1Me Aliases
May 6, 2026
Aug 18, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL.
1Storage Api Project
1Storage Api
May 6, 2026
Aug 18, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unkno...Show more
The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.Show less
1Picketlink
1Picketlink
May 6, 2026
Aug 17, 2015
N/A· v4
N/A· v3
6.0 MEDIUM· v2
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts v...Show more
The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specified, which allows remote attackers to log in to other users' accounts via a crafted SAML assertion. NOTE: this identifier has been SPLIT per ADT2 due to different vulnerability types. See CVE-2015-6254 for lack of validation for the Destination attribute in a Response element in a SAML assertion.Show less
1Apple
1Iphone Os
May 6, 2026
Aug 17, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages symlink mishandling.
1Apple
2Iphone Os
Mac Os X
May 6, 2026
Aug 17, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executable file.
1Apple
1Mac Os X
May 6, 2026
Aug 16, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Apple OS X before 10.10.5 does not properly restrict access to the Date & Time preferences pane, which allows local users to spoof the time by visiting this pane.
1Theforeman
1Foreman
May 6, 2026
Aug 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.
1Clutter Project
1Clutter
May 6, 2026
Aug 12, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch gestures.
1Mozilla
1Firefox Os
May 6, 2026
Aug 8, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Mozilla Firefox OS before 2.2 allows physically proximate attackers to bypass the pass-code protection mechanism and access USB Mass Storage (UMS) media volumes by using the USB interface for a mount operation.
2Debian
Wordpress
2Debian Linux
Wordpress
May 6, 2026
Aug 3, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrat...Show more
WordPress before 4.2.3 does not properly verify the edit_posts capability, which allows remote authenticated users to bypass intended access restrictions and create drafts by leveraging the Subscriber role, as demonstrated by a post-quickdraft-save action to wp-admin/post.php.Show less
1Rubyonrails
1Web Console
May 6, 2026
Jul 26, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass...Show more
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.Show less
1Honeywell
1Tuxedo Touch
May 6, 2026
Jul 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-serv...Show more
Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended access restrictions by removing USERACCT requests from the client-server data stream.Show less
1Gemalto
3Safenet Luna G5
Safenet Luna Pci ESafenet Luna Sa
May 6, 2026
Jul 22, 2015
N/A· v4
N/A· v3
1.3 LOW· v2
The Gemalto SafeNet Luna HSM allows remote authenticated users to bypass intended key-export restrictions by leveraging (1) crypto-user or (2) crypto-officer access to an HSM partition.
1Ibm
1Db2
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions an...Show more
The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.Show less