CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 1 of 7
- CVE-2016-5788CRITICALCVSS 10.0EG 10.02016-11-25
General Electric (GE) Bently Nevada 3500/22M USB with firmware before 5.0 and Bently Nevada 3500/22M Serial have open ports, which makes it easier for remote attackers to obtain privileged access via unspecified vectors.
- CVE-2019-15149CRITICALCVSS 9.8EG 9.82019-08-18
core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue beca…
- CVE-2017-8227CRITICALCVSS 9.8EG 9.82019-07-03
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interface provided by the device. However, if the same brute forc…
- CVE-2016-9568CRITICALCVSS 9.8EG 9.82018-02-19
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
- CVE-2011-4889CRITICALCVSS 9.8EG 9.82018-02-08
The javax.naming.directory.AttributeInUseException class in the Virtual Member Manager in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.43, 7.0 before 7.0.0.21, and 8.0 before 8.0.0.2 does not properly update passwords on a confi…
- CVE-2016-0332CRITICALCVSS 9.8EG 9.82018-01-12
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approa…
- CVE-2014-5334CRITICALCVSS 9.8EG 9.82018-01-08
FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.
- CVE-2015-6473CRITICALCVSS 9.8EG 9.82017-08-22
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.
- CVE-2015-9065CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.
- CVE-2016-8964CRITICALCVSS 9.8EG 9.82017-07-13
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
- CVE-2016-10321CRITICALCVSS 9.8EG 9.82017-04-10
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
- CVE-2016-7630CRITICALCVSS 9.8EG 9.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "WebSheet" component, which allows attackers to bypass a sandbox protection mechanism via unspecified vectors.
- CVE-2016-10178CRITICALCVSS 9.8EG 9.82017-01-30
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
- CVE-2015-8857CRITICALCVSS 9.8EG 9.82017-01-23
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by lev…
- CVE-2016-8398CRITICALCVSS 9.8EG 9.82017-01-12
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.
- CVE-2016-9885CRITICALCVSS 9.8EG 9.82017-01-06
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticat…
- CVE-2016-9865CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), …
- CVE-2016-6629CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions…
- CVE-2016-6957CRITICALCVSS 9.8EG 9.82016-10-13
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-6493CRITICALCVSS 9.8EG 9.82016-08-19
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission.
- CVE-2016-4215CRITICALCVSS 9.8EG 9.82016-07-13
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2015-8804CRITICALCVSS 9.8EG 9.82016-02-23
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vec…
- CVE-2015-8803CRITICALCVSS 9.8EG 9.82016-02-23
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact …
- CVE-2015-8286CRITICALCVSS 9.8EG 9.82016-02-18
Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.
- CVE-2016-1896CRITICALCVSS 9.8EG 9.82016-01-27
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrec…
- CVE-2015-7554CRITICALCVSS 9.8EG 9.82016-01-08
The _TIFFVGetField function in tif_dir.c in libtiff 4.0.6 allows attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via crafted field data in an extension tag in a TIFF image.
- CVE-2011-3145CRITICALCVSS 3.8EG 9.82019-04-22
When mount.ecrpytfs_private before version 87-0ubuntu1.2 calls setreuid() it doesn't also set the effective group id. So when it creates the new version, mtab.tmp, it's created with the group id of the user running mount.ecryptfs_private.
- CVE-2016-2296CRITICALCVSS 9.4EG 9.42016-05-14
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
- CVE-2016-6582CRITICALCVSS 9.1EG 9.12017-01-23
The Doorkeeper gem before 4.2.0 for Ruby might allow remote attackers to conduct replay attacks or revoke arbitrary tokens by leveraging failure to implement the OAuth 2.0 Token Revocation specification.
- CVE-2016-5763CRITICALCVSS 9.1EG 9.12016-11-15
Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maint…
- CVE-2014-5414CRITICALCVSS 9.1EG 9.12016-10-05
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force…
- CVE-2015-8914CRITICALCVSS 9.1EG 9.12016-06-17
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via …
- CVE-2016-9470CRITICALCVSS 9.0EG 9.02017-03-28
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over …
- CVE-2014-3150HIGHCVSS 8.8EG 8.82017-11-15
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.
- CVE-2015-7843HIGHCVSS 8.8EG 8.82017-10-03
The management interface on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software befo…
- CVE-2016-5196HIGHCVSS 8.8EG 8.82017-01-19
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, …
- CVE-2016-9028HIGHCVSS 8.8EG 8.82016-10-28
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
- CVE-2016-4475HIGHCVSS 8.8EG 8.82016-08-19
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary org…
- CVE-2016-5145HIGHCVSS 8.8EG 8.82016-08-07
Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass …
- CVE-2016-5132HIGHCVSS 8.8EG 8.82016-07-23
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin …
- CVE-2016-5128HIGHCVSS 8.8EG 8.82016-07-23
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Po…
- CVE-2016-3650HIGHCVSS 8.8EG 8.82016-06-30
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
- CVE-2016-3648HIGHCVSS 8.8EG 8.82016-06-30
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts…
- CVE-2016-4474HIGHCVSS 8.8EG 8.82016-06-30
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which all…
- CVE-2016-2831HIGHCVSS 8.8EG 8.82016-06-13
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or s…
- CVE-2016-1696HIGHCVSS 8.8EG 8.82016-06-05
The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.
- CVE-2016-1672HIGHCVSS 8.8EG 8.82016-06-05
The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attac…
- CVE-2015-7330HIGHCVSS 8.8EG 8.82016-04-11
Puppet Enterprise 2015.3 before 2015.3.1 allows remote attackers to bypass a host whitelist protection mechanism by leveraging the Puppet communications protocol.
- CVE-2015-1142857HIGHCVSS 8.6EG 8.62018-01-23
On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e…
- CVE-2016-6597HIGHCVSS 8.6EG 8.62016-08-10
Sophos EAS Proxy before 6.2.0 for Sophos Mobile Control, when Lotus Traveler is enabled, allows remote attackers to access arbitrary web-resources from the backend mail system via a request for the resource, aka an Open Reverse Proxy vulne…
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →