CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 6 of 7
- CVE-2014-1428MEDIUMCVSS 2.0EG 5.32019-04-22
A vulnerability in generate_filestorage_key of Ubuntu MAAS allows an attacker to brute-force filenames. This issue affects Ubuntu MAAS versions prior to 1.9.2.
- CVE-2016-9347MEDIUMCVSS 5.0EG 5.02017-02-13
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SS…
- CVE-2016-4451MEDIUMCVSS 5.0EG 5.02016-08-19
The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbit…
- CVE-2015-8615MEDIUMCVSS 5.0EG 5.02016-01-08
The hvm_set_callback_via function in arch/x86/hvm/irq.c in Xen 4.6 does not limit the number of printk console messages when logging the new callback method, which allows local HVM guest OS users to cause a denial of service via a large nu…
- CVE-2016-3320MEDIUMCVSS 4.9EG 4.92016-08-09
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafte…
- CVE-2016-10932MEDIUMCVSS 4.8EG 4.82019-08-26
An issue was discovered in the hyper crate before 0.9.4 for Rust on Windows. There is an HTTPS man-in-the-middle vulnerability because hostname verification was omitted.
- CVE-2010-1776MEDIUMCVSS 4.8EG 4.82017-04-24
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to …
- CVE-2016-7959MEDIUMCVSS 4.7EG 4.72016-10-13
Siemens SIMATIC STEP 7 (TIA Portal) before 14 improperly stores pre-shared key data in TIA project files, which makes it easier for local users to obtain sensitive information by leveraging access to a file and conducting a brute-force att…
- CVE-2021-40006MEDIUMCVSS 4.6EG 4.62022-01-10
Vulnerability of design defects in the security algorithm component. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2016-10894MEDIUMCVSS 4.6EG 4.62019-08-16
xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (and thus control) various programs such as Chromium via events such as pan scrolling, "pinch and zoom" gestures, or even…
- CVE-2016-5933MEDIUMCVSS 4.6EG 4.62017-03-08
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.
- CVE-2016-7638MEDIUMCVSS 4.6EG 4.62017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Find My iPhone" component, which allows physically proximate attackers to disable this component by bypassing authentication.
- CVE-2016-7597MEDIUMCVSS 4.6EG 4.62017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to maintain the unlocked state via vectors related to Handoff with …
- CVE-2017-11818MEDIUMCVSS 4.5EG 4.52017-10-13
The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to valida…
- CVE-2016-4412MEDIUMCVSS 4.4EG 4.42016-12-11
An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x …
- CVE-2016-3287MEDIUMCVSS 4.4EG 4.42016-07-13
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative access to install a crafted policy, aka "Se…
- CVE-2017-18467MEDIUMCVSS 4.3EG 4.32019-08-05
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
- CVE-2017-18445MEDIUMCVSS 4.3EG 4.32019-08-02
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
- CVE-2019-10741MEDIUMCVSS 4.3EG 4.32019-04-07
K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if ope…
- CVE-2016-5949MEDIUMCVSS 4.3EG 4.32017-02-01
IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.
- CVE-2016-5898MEDIUMCVSS 4.3EG 4.32017-02-01
IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit this vulnerability to obtain sensitive inf…
- CVE-2015-7976MEDIUMCVSS 4.3EG 4.32017-01-30
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
- CVE-2016-10148MEDIUMCVSS 4.3EG 4.32017-01-18
The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authenticated users to bypass intended read-ac…
- CVE-2016-9209MEDIUMCVSS 4.3EG 4.32016-12-14
A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive…
- CVE-2016-5511MEDIUMCVSS 4.3EG 4.32016-10-25
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 12.2.1.0.0, 12.2.1.1.0, and 12.2.1.2.0 allows remote attackers to affect integrity via unknown vectors.
- CVE-2016-5163MEDIUMCVSS 4.3EG 4.32016-09-11
The bidirectional-text implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux does not ensure left-to-right (LTR) rendering of URLs, which allows remote attackers to spoof the address bar v…
- CVE-2016-5268MEDIUMCVSS 4.3EG 4.32016-08-05
Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL,…
- CVE-2016-4603MEDIUMCVSS 4.3EG 4.32016-07-22
Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.
- CVE-2016-1664MEDIUMCVSS 4.3EG 4.32016-05-14
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remo…
- CVE-2016-1657MEDIUMCVSS 4.3EG 4.32016-04-18
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the ad…
- CVE-2016-1965MEDIUMCVSS 4.3EG 4.32016-03-13
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the lo…
- CVE-2016-1958MEDIUMCVSS 4.3EG 4.32016-03-13
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
- CVE-2015-5331MEDIUMCVSS 4.3EG 4.32016-02-22
Moodle 2.9.x before 2.9.3 does not properly check the contact list before authorizing message transmission, which allows remote authenticated users to bypass intended access restrictions and conduct spam attacks via the messaging API.
- CVE-2016-1616MEDIUMCVSS 4.3EG 4.32016-01-25
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.
- CVE-2015-7269MEDIUMCVSS 4.2EG 4.22017-11-27
Seagate ST500LT015 hard disk drives, when operating in eDrive mode on Lenovo ThinkPad W541 laptops with BIOS 2.21, allow physically proximate attackers to bypass self-encrypting drive (SED) protection by attaching a second SATA connector t…
- CVE-2015-7268MEDIUMCVSS 4.2EG 4.22017-11-27
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when used on Windows and operating in Opal mode on Lenovo ThinkPad T440s laptops with BIOS 2.32 or ThinkPad W541 laptops with BIOS 2.21, o…
- CVE-2015-7267MEDIUMCVSS 4.2EG 4.22017-11-27
Samsung 850 Pro and PM851 solid-state drives and Seagate ST500LT015 and ST500LT025 hard disk drives, when in sleep mode and operating in Opal or eDrive mode on Lenovo ThinkPad T440s laptops with BIOS 2.32; ThinkPad W541 laptops with BIOS 2…
- CVE-2015-0233MEDIUMCVSS 4.2EG 4.22017-08-28
Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38.
- CVE-2015-4960MEDIUMCVSS 4.1EG 4.12016-01-17
IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web …
- CVE-2016-1551LOWCVSS 3.7EG 3.72017-01-27
ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stor…
- CVE-2016-0372LOWCVSS 3.7EG 3.72016-11-24
IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 before 6.0.2 iFix5; Rational Quality Manager 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iF…
- CVE-2016-0353LOWCVSS 3.7EG 3.72016-11-24
IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by in…
- CVE-2016-0240LOWCVSS 3.7EG 3.72016-10-22
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive i…
- CVE-2016-0266LOWCVSS 3.7EG 3.72016-08-08
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.
- CVE-2016-5702LOWCVSS 3.7EG 3.72016-07-03
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
- CVE-2015-7576LOWCVSS 3.7EG 3.72016-02-16
The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2…
- CVE-2016-4751LOWCVSS 3.5EG 3.52016-09-25
The Safari Tabs component in Apple Safari before 10 allows remote attackers to spoof the address bar of a tab via a crafted web site.
- CVE-2016-10772LOWCVSS 3.3EG 3.32019-08-05
cPanel before 60.0.25 does not enforce feature-list restrictions when calling the multilang adminbin (SEC-168).
- CVE-2017-18429LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
- CVE-2016-5525LOWCVSS 3.3EG 3.32016-10-25
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →