CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 5 of 7
- CVE-2016-4741MEDIUMCVSS 5.9EG 5.92016-09-18
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.
- CVE-2016-0907MEDIUMCVSS 5.9EG 5.92016-05-30
EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof S…
- CVE-2016-2115MEDIUMCVSS 5.9EG 5.92016-04-25
Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server da…
- CVE-2016-2114MEDIUMCVSS 5.9EG 5.92016-04-25
The SMB1 protocol implementation in Samba 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "server signing = mandatory" setting, which allows man-in-the-middle attackers to spoof SMB servers by modifying…
- CVE-2016-2112MEDIUMCVSS 5.9EG 5.92016-04-25
The bundled LDAP client library in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 does not recognize the "client ldap sasl wrapping" setting, which allows man-in-the-middle attackers to perform LDAP protocol-do…
- CVE-2016-2110MEDIUMCVSS 5.9EG 5.92016-04-25
The NTLMSSP authentication implementation in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 allows man-in-the-middle attackers to perform protocol-downgrade attacks by modifying the client-server data stream to…
- CVE-2016-0818MEDIUMCVSS 5.9EG 5.92016-03-12
The caching functionality in the TrustManagerImpl class in TrustManagerImpl.java in Conscrypt in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 mishandles the distinction between an intermediate CA and a trust…
- CVE-2016-2047MEDIUMCVSS 5.9EG 5.92016-01-27
The ssl_verify_server_cert function in sql-common/client.c in MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10; Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier; and Percona Server do not p…
- CVE-2017-12353MEDIUMCVSS 5.8EG 5.82017-11-30
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device…
- CVE-2016-4500MEDIUMCVSS 5.8EG 5.82016-06-01
Moxa UC-7408 LX-Plus devices allow remote authenticated users to write to the firmware, and consequently render a device unusable, by leveraging root access.
- CVE-2018-4863MEDIUMCVSS 5.5EG 5.52018-04-05
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.
- CVE-2015-7837MEDIUMCVSS 5.5EG 5.52017-09-19
The Linux kernel, as used in Red Hat Enterprise Linux 7, kernel-rt, and Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended securelevel/secureboot restrictions by leveraging improper handli…
- CVE-2015-3170MEDIUMCVSS 5.5EG 5.52017-07-21
selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy.
- CVE-2016-10336MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
- CVE-2016-10332MEDIUMCVSS 5.5EG 5.52017-06-13
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
- CVE-2015-8986MEDIUMCVSS 5.5EG 5.52017-03-14
Sandbox detection evasion vulnerability in hardware appliances in McAfee (now Intel Security) Advanced Threat Defense (MATD) 3.4.2.32 and earlier allows attackers to detect the sandbox environment, then bypass proper malware detection resu…
- CVE-2016-9868MEDIUMCVSS 5.5EG 5.52017-01-06
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-service by generating a kernel panic in the SCINI driver using IOCTL calls which may render the ScaleIO Data Client (SDC)…
- CVE-2016-5328MEDIUMCVSS 5.5EG 5.52016-12-29
VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
- CVE-2016-6848MEDIUMCVSS 5.5EG 5.52016-12-15
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. API requests can be used to inject, generate and download executable files to the client ("Reflected File Download"). Malicious platform specific (e.g. Microsoft Windo…
- CVE-2016-6708MEDIUMCVSS 5.5EG 5.52016-11-25
An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your work profile in Multi-Window mode. This issue is rated as High because it is a local bypa…
- CVE-2016-4025MEDIUMCVSS 5.5EG 5.52016-11-03
Avast Internet Security v11.x.x, Pro Antivirus v11.x.x, Premier v11.x.x, Free Antivirus v11.x.x, Business Security v11.x.x, Endpoint Protection v8.x.x, Endpoint Protection Plus v8.x.x, Endpoint Protection Suite v8.x.x, Endpoint Protection …
- CVE-2016-3279MEDIUMCVSS 5.5EG 5.52016-07-13
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services…
- CVE-2016-0181MEDIUMCVSS 5.5EG 5.52016-05-11
Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Int…
- CVE-2015-8777MEDIUMCVSS 5.5EG 5.52016-01-20
The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.
- CVE-2016-0274MEDIUMCVSS 5.4EG 5.42018-03-09
IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial Transaction Manager (FTM) for Check Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, and Financial Trans…
- CVE-2016-8911MEDIUMCVSS 5.4EG 5.42017-02-01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack th…
- CVE-2016-8306MEDIUMCVSS 5.4EG 5.42017-01-27
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerab…
- CVE-2016-5623MEDIUMCVSS 5.4EG 5.42017-01-27
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vuln…
- CVE-2016-6626MEDIUMCVSS 5.4EG 5.42016-12-11
An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
- CVE-2021-43177MEDIUMCVSS 5.3EG 5.32022-04-11
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR…
- CVE-2019-10059MEDIUMCVSS 5.3EG 5.32019-08-28
The legacy finger service (TCP port 79) is enabled by default on various older Lexmark devices.
- CVE-2014-6050MEDIUMCVSS 5.3EG 5.32018-08-28
phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
- CVE-2016-9071MEDIUMCVSS 5.3EG 5.32018-06-11
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
- CVE-2014-9635MEDIUMCVSS 5.3EG 5.32017-09-12
Jenkins before 1.586 does not set the HttpOnly flag in a Set-Cookie header for session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to obtain potentially sensitive information via script access to …
- CVE-2014-9634MEDIUMCVSS 5.3EG 5.32017-09-12
Jenkins before 1.586 does not set the secure flag on session cookies when run on Tomcat 7.0.41 or later, which makes it easier for remote attackers to capture cookies by intercepting their transmission within an HTTP session.
- CVE-2015-7225MEDIUMCVSS 5.3EG 5.32017-09-06
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remote or physically proximate attackers with a target user's lo…
- CVE-2016-4890MEDIUMCVSS 5.3EG 5.32017-04-14
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
- CVE-2016-7281MEDIUMCVSS 5.3EG 5.32016-12-20
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
- CVE-2016-9851MEDIUMCVSS 5.3EG 5.32016-12-11
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
- CVE-2016-9850MEDIUMCVSS 5.3EG 5.32016-12-11
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions…
- CVE-2016-4748MEDIUMCVSS 5.3EG 5.32016-09-25
Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.
- CVE-2016-5306MEDIUMCVSS 5.3EG 5.32016-06-30
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HT…
- CVE-2016-4824MEDIUMCVSS 5.3EG 5.32016-06-25
The Wi-Fi Protected Setup (WPS) implementation on Corega CG-WLR300GNV and CG-WLR300GNV-W devices does not restrict the number of PIN authentication attempts, which makes it easier for remote attackers to obtain network access via a brute-f…
- CVE-2015-3412MEDIUMCVSS 5.3EG 5.32016-05-16
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_…
- CVE-2015-5207MEDIUMCVSS 5.3EG 5.32016-05-09
Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by leveraging unspecified methods.
- CVE-2015-8108MEDIUMCVSS 5.3EG 5.32016-04-12
The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to o…
- CVE-2016-0790MEDIUMCVSS 5.3EG 5.32016-04-07
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.
- CVE-2016-0825MEDIUMCVSS 5.3EG 5.32016-03-12
The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leveraging kernel access, as demonstrated by obtaining Signature or SignatureOrSystem access, …
- CVE-2016-0824MEDIUMCVSS 5.3EG 5.32016-03-12
libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via crafted Bitstream data, as demonstrated by obtaining Signature o…
- CVE-2016-0950MEDIUMCVSS 5.3EG 5.32016-02-10
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →