← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Zikula
1Zikula Application Framework
May 6, 2026
Dec 5, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.
1Siemens
1Sicam Pas/pqs
May 6, 2026
Dec 5, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially cra...Show more
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP.Show less
1Siemens
1Sicam Pas/pqs
May 6, 2026
Dec 5, 2016
N/A· v4
7.3 HIGH· v3
7.5 HIGH· v2
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/T...Show more
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP.Show less
1Ibm
1Powerkvm
May 6, 2026
Dec 1, 2016
N/A· v4
6.5 MEDIUM· v3
4.9 MEDIUM· v2
The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.
1Ibm
1Ims Enterprise Suite
May 6, 2026
Nov 30, 2016
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.
1Ibm
1Qradar Security Information And Event Manager
May 6, 2026
Nov 30, 2016
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 mishandles authorization, which allows remote authenticated users to obtain sensitive information via unspecified vectors.
1Lenovo
74Thinkpad 10 Ella 2 Bios
Thinkpad 11e Beema BiosThinkpad 11e Braswell Bios+71 more
May 6, 2026
Nov 30, 2016
N/A· v4
4.4 MEDIUM· v3
4.7 MEDIUM· v2
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. Th...Show more
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.Show less
1Lenovo
1System Interface Foundation
May 6, 2026
Nov 29, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could ru...Show more
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.Show less
1Apache
1Hadoop
May 6, 2026
Nov 29, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary commands with the same privileges as the HDFS service.
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv...Show more
The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a crafted application that makes sendto system calls, related to net/ipv4/tcp_ipv4.c and net/ipv6/tcp_ipv6.c.Show less
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
6.8 MEDIUM· v3
6.2 MEDIUM· v2
drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary code via crafted fragmented packets.
1Linux
1Linux Kernel
May 6, 2026
Nov 28, 2016
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undef...Show more
The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of service (host OS crash) via a certain use of a ModR/M byte in an undefined instruction.Show less
1Ibm
1Bigfix Remote Control
May 6, 2026
Nov 25, 2016
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a brute-force approach.
1Ibm
1Jazz Reporting Service
May 6, 2026
Nov 25, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML d...Show more
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.Show less
1Ibm
1Jazz Reporting Service
May 6, 2026
Nov 25, 2016
N/A· v4
5.0 MEDIUM· v3
6.0 MEDIUM· v2
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended...Show more
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, which allows remote attackers to obtain access by leveraging an unattended workstation.Show less
1Ibm
1Jazz Reporting Service
May 6, 2026
Nov 25, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
1Google
1Android
May 6, 2026
Nov 25, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility...Show more
A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.Show less
1Google
1Android
May 6, 2026
Nov 25, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical...Show more
A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.Show less
1Google
1Android
May 6, 2026
Nov 25, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious applicat...Show more
A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to continually reboot. This issue is rated as Moderate because it is a temporary denial of service that requires a factory reset to fix. Android ID: A-30568284.Show less
1Google
1Android
May 6, 2026
Nov 25, 2016
N/A· v4
4.7 MEDIUM· v3
5.4 MEDIUM· v2
A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a special...Show more
A denial of service vulnerability in Proxy Auto Config in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Android ID: A-30100884.Show less