← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Huawei
1Honor Ws851 Firmware
May 6, 2026
Jun 14, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
4Canonical
DebianLibndp+1 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+7 more
May 6, 2026
Jun 13, 2016
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of s...Show more
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.Show less
2Atheme
Opensuse
3Atheme
LeapOpensuse
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
1Citrix
1Xenserver
May 6, 2026
Jun 13, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Act...Show more
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.Show less
3Canonical
LibimobiledeviceOpensuse
5Leap
LibimobiledeviceLibusbmuxd+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP so...Show more
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.Show less
1Keystone
1Openstack Identity
May 6, 2026
Jun 13, 2016
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a t...Show more
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.Show less
1Bmc
1Bladelogic Server Automation Console
May 6, 2026
Jun 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sendin...Show more
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.Show less
4Canonical
DebianMozilla+1 more
5Debian Linux
FirefoxLeap+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduc...Show more
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.Show less
3Canonical
MozillaOpensuse
4Firefox
LeapOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation perm...Show more
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.Show less
3Canonical
MozillaOpensuse
4Firefox
LeapOpensuse+1 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
4Canonical
DebianMozilla+1 more
5Debian Linux
FirefoxLeap+2 more
May 6, 2026
Jun 13, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
1Puppet
3Puppet
Puppet AgentPuppet Server
May 6, 2026
Jun 10, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decod...Show more
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.Show less
1Abb
1Pcm600
May 6, 2026
Jun 10, 2016
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
1Kmc Controls
1Bac 5051e Firmware
May 6, 2026
Jun 10, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.
4Debian
OpensuseRedhat+1 more
11Debian Linux
Enterprise LinuxEnterprise Linux Desktop+8 more
May 6, 2026
Jun 9, 2016
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
1Canonical
2Lxd
Ubuntu Linux
May 6, 2026
Jun 9, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.
1Redhat
1Openshift
May 6, 2026
Jun 8, 2016
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network reso...Show more
Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.Show less
1Redhat
1Openshift
May 6, 2026
Jun 8, 2016
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access A...Show more
Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.Show less
1Hp
1Discovery And Dependency Mapping Inventory
May 6, 2026
Jun 8, 2016
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object...Show more
HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.Show less
1Xen
1Xen
May 6, 2026
Jun 7, 2016
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories...Show more
The libxl device-handling in Xen through 4.6.x allows local guest OS users with access to the driver domain to cause a denial of service (management tool confusion) by manipulating information in the backend directories in xenstore.Show less