← Back
CWE-693

508 CVEs • Abstraction: Pillar

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

JSON object

Loading...

CVEs (508)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
15Windows 10 1507
Windows 10 1607Windows 10 1809+12 more
Aug 16, 2024
Aug 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Windows SmartScreen Security Feature Bypass Vulnerability
1Nvidia
4Mlnx Gw
Mlnx OsNvda Os Xc+1 more
Dec 26, 2024
Aug 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploi...Show more
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service.Show less
1Apple
1Macos
Dec 9, 2024
Jul 29, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.
1Openfind
1Mail2000
Nov 21, 2024
Jul 15, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the H...Show more
Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability using specific JavaScript code to obtain the session cookie with the HttpOnly flag enabled.Show less
1Microsoft
1Azure Cyclecloud
Nov 21, 2024
Jul 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Azure CycleCloud Elevation of Privilege Vulnerability
1Microsoft
12Windows 10 1507
Windows 10 1607Windows 10 1809+9 more
Nov 21, 2024
Jul 9, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Windows LockDown Policy (WLDP) Security Feature Bypass Vulnerability
1Microsoft
13Windows 10 1507
Windows 10 1607Windows 10 1809+10 more
Nov 21, 2024
Jul 9, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
BitLocker Security Feature Bypass Vulnerability
1Sap
1Sap Basis
Oct 28, 2025
Jul 9, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact o...Show more
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can bypass the configured malware scanner API because of a programming error. This leads to a low impact on the application's confidentiality, integrity, and availability.Show less
1Eskooly
1Eskooly
Apr 16, 2025
Jul 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP Response Header Settings component.
1Artifex
1Ghostscript
Apr 28, 2025
Jul 3, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.
-
-
Mar 24, 2025
Jun 21, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability...Show more
An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.Show less
1Parallels
1Parallels Desktop
Nov 21, 2024
Jun 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attack...Show more
Parallels Desktop Updater Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows local attackers to downgrade Parallels software on affected installations of Parallels Desktop. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Updater service. The issue results from the lack of proper validation of version information before performing an update. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-19481.Show less
1Mattermost
1Mattermost Desktop
Nov 21, 2024
Jun 14, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's syst...Show more
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows a remote attacker to force a victim over the Internet to run arbitrary programs on the victim's system via custom URI schemes.Show less
1Mattermost
1Mattermost Desktop
Nov 21, 2024
Jun 14, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC restrictions on macOS.
1Dropbox
1Dropbox Desktop
Nov 23, 2024
Jun 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User intera...Show more
Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of shared folders. When syncing files from a shared folder belonging to an untrusted account, the Dropbox desktop application does not apply the Mark-of-the-Web to the local files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-23991.Show less
1Microsoft
2Visual Studio 2019
Visual Studio 2022
Nov 21, 2024
Jun 11, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Visual Studio Remote Code Execution Vulnerability
1Mozilla
3Firefox
Firefox EsrThunderbird
Mar 19, 2025
Jun 11, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 1...Show more
By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.Show less
2Fedoraproject
Xen
2Fedora
Xen
Jan 5, 2026
May 16, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equall...Show more
Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html Show less
1Microsoft
14Windows 10 1507
Windows 10 1607Windows 10 1809+11 more
Jan 8, 2025
May 14, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Windows Mark of the Web Security Feature Bypass Vulnerability
1Microsoft
1Bing Search
Jan 8, 2025
May 14, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Microsoft Bing Search Spoofing Vulnerability