← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Adobe
Redhat
5Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+2 more
May 6, 2026
Oct 13, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
1Sap
1Sapcryptolib
May 6, 2026
Oct 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223...Show more
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to impersonate arbitrary users via unspecified vectors, aka SAP Security Note 2223008.Show less
1Sap
1Netweaver
May 6, 2026
Oct 13, 2016
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlie...Show more
SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remote Function Modules (RFM) by leveraging a connection created from earlier execution of an anonymous RFM included in a Communication Assembly, aka SAP Security Note 2139366.Show less
1Siemens
1Automation License Manager
May 6, 2026
Oct 13, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets.
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal...Show more
The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal bug 28838221.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked Wi-Fi usage) via a crafted application, aka internal bug 30230534.
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a crafted application, aka internal bug 306...Show more
The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and consequently gain privileges via a crafted application, aka internal bug 30647115.Show less
1Google
1Android
May 6, 2026
Oct 10, 2016
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (reboot) via an access point that provid...Show more
Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (reboot) via an access point that provides a crafted (1) Venue Group or (2) Venue Type value, aka internal bug 29464811.Show less
1Redhat
1Cloudforms Management Engine
May 6, 2026
Oct 7, 2016
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary sh...Show more
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.Show less
3Fedoraproject
GnuOpensuse
3Fedora
GlibcOpensuse
May 6, 2026
Oct 7, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to ca...Show more
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.Show less
1Simple Image Manipulator Project
1Simple Image Manipulator
May 6, 2026
Oct 6, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Remote file download in simple-image-manipulator v1.0 wordpress plugin
1Google Adsense And Hotel Booking Project
1Google Adsense And Hotel Booking
May 6, 2026
Oct 6, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05
1F5
1Big Ip Local Traffic Manager
May 6, 2026
Oct 5, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before...Show more
F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or extract system configuration files via vectors involving NAT64.Show less
1Sap
3Netweaver
Sap AbaSap Basis
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, ak...Show more
The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.Show less
1Ibm
1Websphere Application Server
May 6, 2026
Oct 5, 2016
N/A· v4
7.5 HIGH· v3
6.5 MEDIUM· v2
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a...Show more
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.Show less
2Canonical
Clamav
2Clamav
Ubuntu Linux
May 6, 2026
Oct 3, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.
2Canonical
Clamav
2Clamav
Ubuntu Linux
May 6, 2026
Oct 3, 2016
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.
1F5
8Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Application Acceleration Manager+5 more
May 6, 2026
Oct 3, 2016
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit P...Show more
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors.Show less
1Google
1Chrome
May 6, 2026
Sep 29, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.
1Huawei
1Anyoffice Secureapp
May 6, 2026
Sep 26, 2016
N/A· v4
6.5 MEDIUM· v3
7.1 HIGH· v2
Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.