CWE-358
133 CVEs • Abstraction: Base
Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
CVEs (133)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105). |
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92). |
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). |
2Heimdal Project Samba2Heimdal SambaNov 21, 2024 Jul 31, 2019 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could...Show more |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exi...Show more |
1Redhat 2Jboss Enterprise Application Platform WildflyJun 17, 2026 May 3, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time h...Show more |
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security p...Show more |
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at a...Show more |
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a probl...Show more |
2Mozilla Redhat7Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+4 moreNov 21, 2024 Aug 1, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to s...Show more |
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instea...Show more |
1Dell 4Idrac6 Firmware Idrac7 FirmwareIdrac8 Firmware+1 moreNov 21, 2024 Jul 2, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit...Show more |
1Cisco 1Digital Network Architecture Center Nov 21, 2024 May 17, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnera...Show more |
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371). |
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK. |
2Jenkins Redhat2Jenkins OpenshiftNov 21, 2024 May 8, 2018 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing...Show more |
2Oracle Vmware19Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+16 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
4Debian OracleRedhat+1 more28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Se...Show more |
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist...Show more |