CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 2 of 7
- CVE-2015-8801LOWCVSS 2.9EG 2.92016-06-30
Race condition in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6 MP5 allows local users to bypass intended restrictions on USB file transfer by conducting filesystem operations before the SEP device manager recognizes a n…
- CVE-2015-8803CRITICALCVSS 9.8EG 9.82016-02-23
The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact …
- CVE-2015-8804CRITICALCVSS 9.8EG 9.82016-02-23
x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vec…
- CVE-2015-8857CRITICALCVSS 9.8EG 9.82017-01-23
The uglify-js package before 2.4.24 for Node.js does not properly account for non-boolean values when rewriting boolean expressions, which might allow attackers to bypass security mechanisms or possibly have unspecified other impact by lev…
- CVE-2015-8914CRITICALCVSS 9.1EG 9.12016-06-17
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via …
- CVE-2015-8986MEDIUMCVSS 5.5EG 5.52017-03-14
Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resu…
- CVE-2015-8990HIGHCVSS 7.5EG 7.52017-03-14
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.
- CVE-2015-9065CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a UE can respond to a UEInformationRequest before Access Stratum security is established.
- CVE-2015-9243MEDIUMCVSS 5.9EG 5.92018-05-29
When server level, connection level or route level CORS configurations in hapi node module before 11.1.4 are combined and when a higher level config included security restrictions (like origin), a higher level config that included security…
- CVE-2015-9318HIGHCVSS 7.5EG 7.52019-08-20
The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
- CVE-2015-9331HIGHCVSS 7.5EG 7.52019-08-20
The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.
- CVE-2016-0019HIGHCVSS 8.1EG 8.12016-01-13
The Remote Desktop Protocol (RDP) service implementation in Microsoft Windows 10 Gold and 1511 allows remote attackers to bypass intended access restrictions and establish sessions for blank-password accounts via a modified RDP client, aka…
- CVE-2016-0128MEDIUMCVSS 6.8EG 6.82016-04-12
The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establi…
- CVE-2016-0137LOWCVSS 3.3EG 3.32016-09-14
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."
- CVE-2016-0158MEDIUMCVSS 6.5EG 6.52016-04-12
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161.
- CVE-2016-0161HIGHCVSS 6.5EG 8.32016-04-12
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.
- CVE-2016-0181MEDIUMCVSS 5.5EG 5.52016-05-11
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Int…
- CVE-2016-0240LOWCVSS 3.7EG 3.72016-10-22
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive i…
- CVE-2016-0266LOWCVSS 3.7EG 3.72016-08-08
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
- CVE-2016-0274MEDIUMCVSS 5.4EG 5.42018-03-09
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Trans…
- CVE-2016-0287HIGHCVSS 7.8EG 7.82016-07-08
IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.
- CVE-2016-0332CRITICALCVSS 9.8EG 9.82018-01-12
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not properly restrict failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force approa…
- CVE-2016-0353LOWCVSS 3.7EG 3.72016-11-24
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by in…
- CVE-2016-0372LOWCVSS 3.7EG 3.72016-11-24
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iF…
- CVE-2016-0734MEDIUMCVSS 6.1EG 6.12016-04-07
The web-based administration console in Apache ActiveMQ 5.x before 5.13.2 does not send an X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web page that contains a (1) F…
- CVE-2016-0790MEDIUMCVSS 5.3EG 5.32016-04-07
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
- CVE-2016-0818MEDIUMCVSS 5.9EG 5.92016-03-12
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trust…
- CVE-2016-0824MEDIUMCVSS 5.3EG 5.32016-03-12
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature o…
- CVE-2016-0825MEDIUMCVSS 5.3EG 5.32016-03-12
The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, …
- CVE-2016-0828HIGHCVSS 7.5EG 7.52016-03-12
The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obta…
- CVE-2016-0829HIGHCVSS 7.5EG 7.52016-03-12
The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, whi…
- CVE-2016-0832MEDIUMCVSS 6.1EG 6.12016-03-12
Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.
- CVE-2016-0894MEDIUMCVSS 6.3EG 6.32016-05-03
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified parameter.
- CVE-2016-0896HIGHCVSS 7.3EG 7.32016-09-18
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by …
- CVE-2016-0907MEDIUMCVSS 5.9EG 5.92016-05-30
EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof S…
- CVE-2016-0950MEDIUMCVSS 5.3EG 5.32016-02-10
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
- CVE-2016-1000009HIGHCVSS 7.5EG 7.52016-10-06
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.
- CVE-2016-10148MEDIUMCVSS 4.3EG 4.32017-01-18
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-ac…
- CVE-2016-10178CRITICALCVSS 9.8EG 9.82017-01-30
An issue was discovered on the D-Link DWR-932B router. HELODBG on port 39889 (UDP) launches the "/sbin/telnetd -l /bin/sh" command.
- CVE-2016-10185HIGHCVSS 7.5EG 7.52017-01-30
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
- CVE-2016-10224HIGHCVSS 7.2EG 7.22017-02-13
An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.
- CVE-2016-10321CRITICALCVSS 9.8EG 9.82017-04-10
web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.
- CVE-2016-10332MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
- CVE-2016-10336MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
- CVE-2016-10443MEDIUMCVSS 6.8EG 6.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425…
- CVE-2016-10517HIGHCVSS 7.4EG 7.42017-10-24
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TC…
- CVE-2016-10552HIGHCVSS 7.4EG 7.42018-05-31
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
- CVE-2016-10717HIGHCVSS 7.8EG 7.82018-03-21
A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIV…
- CVE-2016-10746HIGHCVSS 7.5EG 7.52019-04-18
libvirt-domain.c in libvirt before 1.3.1 supports virDomainGetTime API calls by guest agents with an RO connection, even though an RW connection was supposed to be required, a different vulnerability than CVE-2019-3886.
- CVE-2016-10772LOWCVSS 3.3EG 3.32019-08-05
cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →