CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 3 of 7
- CVE-2016-3400HIGHCVSS 7.5EG 7.52017-07-03
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
- CVE-2016-9738HIGHCVSS 7.5EG 7.52017-06-27
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.
- CVE-2016-6594HIGHCVSS 7.5EG 7.52017-06-08
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
- CVE-2016-5057HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
- CVE-2016-5052HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
- CVE-2016-7797HIGHCVSS 7.5EG 7.52017-03-24
Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection.
- CVE-2015-8990HIGHCVSS 7.5EG 7.52017-03-14
Detection bypass vulnerability in Intel Security Advanced Threat Defense (ATD) 3.4.6 and earlier allows malware samples to bypass ATD detection via renaming the malware.
- CVE-2016-4689HIGHCVSS 7.5EG 7.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature that used a revoked certificate.
- CVE-2016-10185HIGHCVSS 7.5EG 7.52017-01-30
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.
- CVE-2016-6497HIGHCVSS 7.5EG 7.52017-01-18
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.
- CVE-2016-6271HIGHCVSS 7.5EG 7.52017-01-18
The Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing HVI check on DHPart2 packet reception.
- CVE-2016-9861HIGHCVSS 7.5EG 7.52016-12-11
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.…
- CVE-2016-6460HIGHCVSS 7.5EG 7.52016-11-19
A vulnerability in the FTP Representational State Transfer Application Programming Interface (REST API) for Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass FTP malware detection rules and download …
- CVE-2016-7989HIGHCVSS 7.5EG 7.52016-10-31
On Samsung Galaxy S4 through S7 devices, a malformed OTA WAP PUSH SMS containing an OMACP message sent remotely triggers an unhandled ArrayIndexOutOfBoundsException in Samsung's implementation of the WifiServiceImpl class within wifi-servi…
- CVE-2016-8600HIGHCVSS 7.5EG 7.52016-10-28
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
- CVE-2016-1000009HIGHCVSS 7.5EG 7.52016-10-06
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.
- CVE-2016-7401HIGHCVSS 7.5EG 7.52016-10-03
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.
- CVE-2016-7031HIGHCVSS 7.5EG 7.52016-10-03
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.
- CVE-2016-6639HIGHCVSS 7.5EG 7.52016-09-18
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file…
- CVE-2016-1438HIGHCVSS 7.5EG 7.52016-06-23
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.
- CVE-2016-3163HIGHCVSS 7.5EG 7.52016-04-12
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
- CVE-2015-5303HIGHCVSS 7.5EG 7.52016-04-11
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataPro…
- CVE-2016-2193HIGHCVSS 7.5EG 7.52016-04-11
PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.
- CVE-2016-3125HIGHCVSS 7.5EG 7.52016-04-05
The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to ha…
- CVE-2016-0829HIGHCVSS 7.5EG 7.52016-03-12
The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, whi…
- CVE-2016-0828HIGHCVSS 7.5EG 7.52016-03-12
The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obta…
- CVE-2015-5267HIGHCVSS 7.5EG 7.52016-02-22
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string functions, which makes it easier for re…
- CVE-2016-2041HIGHCVSS 7.5EG 7.52016-02-20
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended ac…
- CVE-2016-1927HIGHCVSS 7.5EG 7.52016-02-20
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess password…
- CVE-2015-5010HIGHCVSS 7.5EG 7.52016-02-15
IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to obtain access via a b…
- CVE-2016-1296HIGHCVSS 7.5EG 7.52016-01-20
The proxy engine on Cisco Web Security Appliance (WSA) devices with software 8.5.3-055, 9.1.0-000, and 9.5.0-235 allows remote attackers to bypass intended proxy restrictions via a malformed HTTP method, aka Bug ID CSCux00848.
- CVE-2016-8615HIGHCVSS 5.3EG 7.52018-08-01
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie…
- CVE-2002-0493HIGHCVSS v2 7.5EG 7.52002-08-12
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
- CVE-2016-10552HIGHCVSS 7.4EG 7.42018-05-31
igniteui 0.0.5 and earlier downloads JavaScript and CSS resources over insecure protocol.
- CVE-2016-10517HIGHCVSS 7.4EG 7.42017-10-24
networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TC…
- CVE-2015-8400HIGHCVSS 7.4EG 7.42016-01-12
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
- CVE-2016-3102HIGHCVSS 7.3EG 7.32017-02-09
The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.
- CVE-2016-8310HIGHCVSS 7.3EG 7.32017-01-27
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exp…
- CVE-2016-8503HIGHCVSS 7.3EG 7.32016-10-26
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
- CVE-2016-8502HIGHCVSS 7.3EG 7.32016-10-26
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
- CVE-2016-0896HIGHCVSS 7.3EG 7.32016-09-18
Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by …
- CVE-2016-10224HIGHCVSS 7.2EG 7.22017-02-13
An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure that the cookie is valid for the associated user.
- CVE-2000-0277HIGHCVSS v2 7.2EG 7.22000-04-03
Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
- CVE-2017-11579HIGHCVSS 7.1EG 7.12019-07-02
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to …
- CVE-2016-2867HIGHCVSS 7.0EG 7.02016-07-02
IBM InfoSphere Streams before 4.0.1.2 and IBM Streams before 4.1.1.1 do not properly implement the runAsUser feature, which allows local users to obtain root group privileges via unspecified vectors.
- CVE-2016-10443MEDIUMCVSS 6.8EG 6.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425…
- CVE-2015-6592MEDIUMCVSS 6.8EG 6.82017-09-25
Huawei UAP2105 before V300R012C00SPC160(BootRom) does not require authentication to the serial port or the VxWorks shell.
- CVE-2016-7601MEDIUMCVSS 6.8EG 6.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Local Authentication" component, which does not honor the configured screen-lock time interval if the Touch ID prompt is visible.
- CVE-2016-4781MEDIUMCVSS 6.8EG 6.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unsp…
- CVE-2016-2312MEDIUMCVSS 6.8EG 6.82016-12-23
Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →