CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 4 of 7
- CVE-2016-3128HIGHCVSS 8.2EG 8.22017-01-13
A spoofing vulnerability in the Core of BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote attackers to enroll an illegitimate device to the BES, gain access to device parameters for the BES, or send false information to th…
- CVE-2016-3163HIGHCVSS 7.5EG 7.52016-04-12
The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.
- CVE-2016-3168MEDIUMCVSS 6.4EG 6.42016-04-12
The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected…
- CVE-2016-3180HIGHCVSS 8.1EG 8.12017-02-07
Tor Browser Launcher (aka torbrowser-launcher) before 0.2.4, during the initial run, allows man-in-the-middle attackers to bypass the PGP signature verification and execute arbitrary code via a Trojan horse tar file and a signature file wi…
- CVE-2016-3198MEDIUMCVSS 6.5EG 6.62016-06-16
Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
- CVE-2016-3238HIGHCVSS 8.1EG 8.22016-07-13
The Print Spooler service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows man-in-the-middle attackers to e…
- CVE-2016-3279MEDIUMCVSS 5.5EG 5.52016-07-13
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services…
- CVE-2016-3287MEDIUMCVSS 4.4EG 4.42016-07-13
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Se…
- CVE-2016-3320MEDIUMCVSS 4.9EG 4.92016-08-09
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafte…
- CVE-2016-3353HIGHCVSS 8.3EG 8.32016-09-14
Microsoft Internet Explorer 9 through 11 mishandles .url files from the Internet zone, which allows remote attackers to bypass intended access restrictions via a crafted file, aka "Internet Explorer Security Feature Bypass."
- CVE-2016-3354LOWCVSS 3.3EG 3.32016-09-14
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to …
- CVE-2016-3400HIGHCVSS 7.5EG 7.52017-07-03
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
- CVE-2016-3648HIGHCVSS 8.8EG 8.82016-06-30
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechanism, and conduct brute-force password-guessing attacks against management-console accounts…
- CVE-2016-3650HIGHCVSS 8.8EG 8.82016-06-30
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.
- CVE-2016-3672HIGHCVSS 7.8EG 7.82016-04-27
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOM…
- CVE-2016-3676MEDIUMCVSS 6.4EG 6.42016-04-11
Huawei E3276s USB modems with software before E3276s-150TCPU-V200R002B436D09SP00C00 allow man-in-the-middle attackers to intercept, spoof, or modify network traffic via unspecified vectors related to a fake network.
- CVE-2016-3677MEDIUMCVSS 6.5EG 6.52016-06-13
The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.
- CVE-2016-3752HIGHCVSS 7.8EG 7.82016-07-11
internal/app/ChooserActivity.java in the ChooserTarget service in Android 6.x before 2016-07-01 mishandles target security checks, which allows attackers to gain privileges via a crafted application, aka internal bug 28384423.
- CVE-2016-3997HIGHCVSS 7.5EG 7.52017-07-03
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
- CVE-2016-4025MEDIUMCVSS 5.5EG 5.52016-11-03
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection …
- CVE-2016-4215CRITICALCVSS 9.8EG 9.82016-07-13
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScript API execution res…
- CVE-2016-4376MEDIUMCVSS 6.5EG 6.52016-08-22
HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B switches allows remote attackers to obtain sensitive information via unspecified vectors.
- CVE-2016-4394MEDIUMCVSS 6.5EG 6.52016-10-28
HPE System Management Homepage before v7.6 allows remote attackers to obtain sensitive information via unspecified vectors, related to an "HSTS" issue.
- CVE-2016-4412MEDIUMCVSS 4.4EG 4.42016-12-11
An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x …
- CVE-2016-4451MEDIUMCVSS 5.0EG 5.02016-08-19
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbit…
- CVE-2016-4474HIGHCVSS 8.8EG 8.82016-06-30
The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) director (aka overcloud-full) use a default root password of ROOTPW, which all…
- CVE-2016-4475HIGHCVSS 8.8EG 8.82016-08-19
The (1) Organization and (2) Locations APIs and UIs in Foreman before 1.11.4 and 1.12.x before 1.12.0-RC3 allow remote authenticated users to bypass organization and location restrictions and (a) read, (b) edit, or (c) delete arbitrary org…
- CVE-2016-4500MEDIUMCVSS 5.8EG 5.82016-06-01
Moxa UC-7408 LX-Plus devices allow remote authenticated users to write to the firmware, and consequently render a device unusable, by leveraging root access.
- CVE-2016-4603MEDIUMCVSS 4.3EG 4.32016-07-22
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
- CVE-2016-4642MEDIUMCVSS 5.9EG 5.92019-01-11
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warni…
- CVE-2016-4689HIGHCVSS 7.5EG 7.52017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature that used a revoked certificate.
- CVE-2016-4721MEDIUMCVSS 5.9EG 5.92017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allows man-in-the-middle attackers to spoof calls via a "switch …
- CVE-2016-4741MEDIUMCVSS 5.9EG 5.92016-09-18
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
- CVE-2016-4748MEDIUMCVSS 5.3EG 5.32016-09-25
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
- CVE-2016-4751LOWCVSS 3.5EG 3.52016-09-25
The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
- CVE-2016-4781MEDIUMCVSS 6.8EG 6.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unsp…
- CVE-2016-4824MEDIUMCVSS 5.3EG 5.32016-06-25
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-f…
- CVE-2016-4890MEDIUMCVSS 5.3EG 5.32017-04-14
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
- CVE-2016-5052HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
- CVE-2016-5057HIGHCVSS 7.5EG 7.52017-04-10
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
- CVE-2016-5091HIGHCVSS 8.1EG 8.12017-01-23
Extbase in TYPO3 4.3.0 before 6.2.24, 7.x before 7.6.8, and 8.1.1 allows remote attackers to obtain sensitive information or possibly execute arbitrary code via a crafted Extbase action.
- CVE-2016-5117MEDIUMCVSS 5.9EG 5.92017-01-31
OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp constraint with a valid certificate.
- CVE-2016-5128HIGHCVSS 8.8EG 8.82016-07-23
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Po…
- CVE-2016-5132HIGHCVSS 8.8EG 8.82016-07-23
The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin …
- CVE-2016-5145HIGHCVSS 8.8EG 8.82016-08-07
Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass …
- CVE-2016-5155MEDIUMCVSS 6.5EG 6.52016-09-11
Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly validate access to the initial document, which allows remote attackers to spoof the address bar via a crafted web site.
- CVE-2016-5160MEDIUMCVSS 6.5EG 6.52016-09-11
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessib…
- CVE-2016-5162MEDIUMCVSS 6.5EG 6.52016-09-11
The AllowCrossRendererResourceLoad function in extensions/browser/url_request_util.cc in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not properly use an extension's manifest.json web_accessib…
- CVE-2016-5163MEDIUMCVSS 4.3EG 4.32016-09-11
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar v…
- CVE-2016-5196HIGHCVSS 8.8EG 8.82017-01-19
The content renderer client in Google Chrome prior to 54.0.2840.85 for Android insufficiently enforced the Same Origin Policy amongst downloaded files, which allowed a remote attacker to access any downloaded file and interact with sites, …
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →