← Back
CWE-284

7,447 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (7,447)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Opensuse
OracleRedhat+1 more
21Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Eus Compute Node+18 more
Apr 22, 2026
Oct 22, 2015
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment.
1Mozilla
1Firefox
May 6, 2026
Oct 18, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is im...Show more
The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Revive Adserver
1Revive Adserver
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows remote attackers to conduct cross domain attacks via unspecified vectors.
1Revive Adserver
1Revive Adserver
May 6, 2026
Oct 14, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) deleted or (2) unlinked.
1Google
1Chrome
May 6, 2026
Oct 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) o...Show more
object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, which allows remote attackers to bypass the Same Origin Policy via a (1) observe or (2) getNotifier call.Show less
1Apple
1Mac Os X
May 6, 2026
Oct 9, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents a Kerberos authenticated request.
1Ibm
1Openpages Grc Platform
May 6, 2026
Oct 3, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
IBM OpenPages GRC Platform 6.2 before IF7, 6.2.1 before 6.2.1.1 IF5, 7.0 before FP4, and 7.1 before FP1 allows remote authenticated users to modify arbitrary user filters via a JSON request.
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate atta...Show more
packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters in the passwordEntry input field, which allows physically proximate attackers to bypass intended access restrictions via a long password that triggers a SystemUI crash, aka internal bug 22214934.Show less
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the...Show more
The getRunningAppProcesses function in services/core/java/com/android/server/am/ActivityManagerService.java in Android before 5.1.1 LMY48I allows attackers to bypass intended getRecentTasks restrictions and discover the name of the foreground application via a crafted application, aka internal bug 20034603.Show less
1Google
1Android
May 6, 2026
Oct 1, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application...Show more
The AppWidgetServiceImpl implementation in com/android/server/appwidget/AppWidgetServiceImpl.java in the Settings application in Android before 5.1.1 LMY48I allows attackers to obtain a URI permission via an application that sends an Intent with a (1) FLAG_GRANT_READ_URI_PERMISSION or (2) FLAG_GRANT_WRITE_URI_PERMISSION flag, as demonstrated by bypassing intended restrictions on reading contacts, aka internal bug 19618745.Show less
1Cubecart
1Cubecart
May 6, 2026
Sep 28, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a r...Show more
classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, which allows remote attackers to change the administrator password via a recovery request with a space character in the validate parameter and the administrator email in the email parameter.Show less
1Drupaldise
1Cms Updater
May 6, 2026
Sep 21, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" p...Show more
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.Show less
1Apple
3Iphone Os
Mac Os XWatchos
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access to the task ports of arbitrary processes by leveraging root privileges.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
SpringBoard in Apple iOS before 9 allows physically proximate attackers to bypass a lock-screen preview-disabled setting, and reply to an audio message, via unspecified vectors.
1Apple
1Iphone Os
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
SpringBoard in Apple iOS before 9 does not properly restrict access to privileged API calls, which allows attackers to spoof the dialog windows of an arbitrary app via a crafted app.
1Apple
2Iphone Os
Safari
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Poli...Show more
WebKit in Apple iOS before 9 does not properly select the cases in which a Cascading Style Sheets (CSS) document is required to have the text/css content type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.Show less
1Unit4
1Teta Web
May 6, 2026
Sep 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted "received...Show more
Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules, which allows remote attackers to gain privileges via crafted "received parameters."Show less
1Siemens
1Ruggedcom Rugged Operating System
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Siemens RUGGEDCOM ROS 3.8.0 through 4.1.x permanently enables the IP forwarding feature, which allows remote attackers to bypass a VLAN isolation protection mechanism via IP traffic.
1Microsoft
3Windows 10
Windows 8.1Windows Server 2012
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V...Show more
Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 improperly processes ACL settings, which allows local users to bypass intended network-traffic restrictions via a crafted application, aka "Hyper-V Security Feature Bypass Vulnerability."Show less
1Microsoft
4Windows 7
Windows 8Windows 8.1+1 more
May 6, 2026
Sep 9, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Medi...Show more
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."Show less