CWE-693
508 CVEs • Abstraction: Pillar
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CVEs (508)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 15Windows 10 1507 Windows 10 1607Windows 10 1809+12 moreAug 16, 2024 Aug 13, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Windows SmartScreen Security Feature Bypass Vulnerability |
1Nvidia 4Mlnx Gw Mlnx OsNvda Os Xc+1 moreDec 26, 2024 Aug 8, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploi...Show more |
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions. |
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the H...Show more |
Azure CycleCloud Elevation of Privilege Vulnerability |
1Microsoft 12Windows 10 1507 Windows 10 1607Windows 10 1809+9 moreNov 21, 2024 Jul 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability |
1Microsoft 13Windows 10 1507 Windows 10 1607Windows 10 1809+10 moreNov 21, 2024 Jul 9, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 BitLocker Security Feature Bypass Vulnerability |
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact o...Show more |
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component. |
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device. |
An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability...Show more |
Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attack...Show more |
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's syst...Show more |
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS. |
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User intera...Show more |
1Microsoft 2Visual Studio 2019 Visual Studio 2022Nov 21, 2024 Jun 11, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 Visual Studio Remote Code Execution Vulnerability |
1Mozilla 3Firefox Firefox EsrThunderbirdMar 19, 2025 Jun 11, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 1...Show more |
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equall...Show more |
1Microsoft 14Windows 10 1507 Windows 10 1607Windows 10 1809+11 moreJan 8, 2025 May 14, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Windows Mark of the Web Security Feature Bypass Vulnerability |
Microsoft Bing Search Spoofing Vulnerability |