CWE-254
308 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-254page 6 of 7
- CVE-2016-8314LOWCVSS 3.1EG 3.12017-01-27
Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Difficult to exploit vulnerability allows low pri…
- CVE-2016-8329MEDIUMCVSS 6.1EG 6.12017-01-27
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Mobile Application Platform). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows una…
- CVE-2016-8398CRITICALCVSS 9.8EG 9.82017-01-12
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.
- CVE-2016-8502HIGHCVSS 7.3EG 7.32016-10-26
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
- CVE-2016-8503HIGHCVSS 7.3EG 7.32016-10-26
Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7 to 16.9 could be used by remote attacker for brute-forcing passwords from important web-resource with special JavaScript.
- CVE-2016-8508MEDIUMCVSS 6.5EG 6.52017-03-01
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own maliciou…
- CVE-2016-8600HIGHCVSS 7.5EG 7.52016-10-28
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
- CVE-2016-8615HIGHCVSS 5.3EG 7.52018-08-01
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie…
- CVE-2016-8768HIGHCVSS 7.8EG 7.82017-04-02
Huawei Honor 6, Honor 6 Plus, Honor 7 phones with software versions earlier than 6.9.16 could allow attackers to disable the PXN defense mechanism by invoking related drive code to crash the system or escalate privilege.
- CVE-2016-8911MEDIUMCVSS 5.4EG 5.42017-02-01
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack th…
- CVE-2016-8964CRITICALCVSS 9.8EG 9.82017-07-13
IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.
- CVE-2016-9010MEDIUMCVSS 6.1EG 6.12017-02-15
IBM WebSphere Message Broker 9.0 and 10.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the vic…
- CVE-2016-9028HIGHCVSS 8.8EG 8.82016-10-28
Unauthorized redirect vulnerability in Citrix NetScaler ADC before 10.1 135.8, 10.5 61.11, 11.0 65.31/65.35F and 11.1 47.14 allows a remote attacker to steal session cookies of a legitimate AAA user via manipulation of Host header.
- CVE-2016-9071MEDIUMCVSS 5.3EG 5.32018-06-11
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
- CVE-2016-9072HIGHCVSS 7.5EG 7.52018-06-11
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected.…
- CVE-2016-9111MEDIUMCVSS 6.8EG 6.82016-11-07
Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the…
- CVE-2016-9160HIGHCVSS 8.1EG 8.12016-12-17
A vulnerability in SIEMENS SIMATIC WinCC (All versions < SIMATIC WinCC V7.2) and SIEMENS SIMATIC PCS 7 (All versions < SIMATIC PCS 7 V8.0 SP1) could allow a remote attacker to crash an ActiveX component or leak parts of the application mem…
- CVE-2016-9207MEDIUMCVSS 6.5EG 6.52016-12-14
A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections to arbitrary hosts. This does not allow for full traffic proxy through the Expressway. Aff…
- CVE-2016-9209MEDIUMCVSS 4.3EG 4.32016-12-14
A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following Cisco products are vulnerable: Adaptive…
- CVE-2016-9347MEDIUMCVSS 5.0EG 5.02017-02-13
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SS…
- CVE-2016-9470CRITICALCVSS 9.0EG 9.02017-03-28
Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable to the fairly new Reflected File Download (RFD) web attack vector that enables attackers to gain complete control over …
- CVE-2016-9568CRITICALCVSS 9.8EG 9.82018-02-19
A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
- CVE-2016-9738HIGHCVSS 7.5EG 7.52017-06-27
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.
- CVE-2016-9850MEDIUMCVSS 5.3EG 5.32016-12-11
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions…
- CVE-2016-9851MEDIUMCVSS 5.3EG 5.32016-12-11
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
- CVE-2016-9861HIGHCVSS 7.5EG 7.52016-12-11
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.…
- CVE-2016-9865CRITICALCVSS 9.8EG 9.82016-12-11
An issue was discovered in phpMyAdmin. Due to a bug in serialized string parsing, it was possible to bypass the protection offered by PMA_safeUnserialize() function. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), …
- CVE-2016-9868MEDIUMCVSS 5.5EG 5.52017-01-06
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-service by generating a kernel panic in the SCINI driver using IOCTL calls which may render the ScaleIO Data Client (SDC)…
- CVE-2016-9885CRITICALCVSS 9.8EG 9.82017-01-06
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticat…
- CVE-2016-9895MEDIUMCVSS 6.1EG 6.12018-06-11
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
- CVE-2016-9900HIGHCVSS 7.5EG 7.52018-06-11
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < …
- CVE-2017-1000406HIGHCVSS 7.5EG 7.52017-11-30
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).
- CVE-2017-11579HIGHCVSS 7.1EG 7.12019-07-02
In the most recent firmware for Blipcare, the device provides an open Wireless network called "Blip" for communicating with the device. The user connects to this open Wireless network and uses the web management interface of the device to …
- CVE-2017-11818MEDIUMCVSS 4.5EG 4.52017-10-13
The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to valida…
- CVE-2017-12353MEDIUMCVSS 5.8EG 5.82017-11-30
A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured user filters on the device…
- CVE-2017-13718HIGHCVSS 8.0EG 8.02019-06-10
The HTTP API supported by Starry Station (aka Starry Router) allows brute forcing the PIN setup by the user on the device, and this allows an attacker to change the Wi-Fi settings and PIN, as well as port forward and expose any internal de…
- CVE-2017-18429LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
- CVE-2017-18445MEDIUMCVSS 4.3EG 4.32019-08-02
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
- CVE-2017-18462HIGHCVSS 7.5EG 7.52019-08-05
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
- CVE-2017-18467MEDIUMCVSS 4.3EG 4.32019-08-05
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
- CVE-2017-18476HIGHCVSS 7.5EG 7.52019-08-05
Leech Protect in cPanel before 62.0.4 does not protect certain directories (SEC-205).
- CVE-2017-18477MEDIUMCVSS 6.5EG 6.52019-08-05
In cPanel before 62.0.4, Exim transports could execute in the context of the nobody account (SEC-206).
- CVE-2017-18480MEDIUMCVSS 6.5EG 6.52019-08-05
cPanel before 62.0.4 does not enforce account ownership for has_mycnf_for_cpuser WHM API calls (SEC-210).
- CVE-2017-2411MEDIUMCVSS 5.9EG 5.92019-01-11
In iOS before 11.2, exchange rates were retrieved from HTTP rather than HTTPS. This was addressed by enabling HTTPS for exchange rates.
- CVE-2017-2748HIGHCVSS 7.5EG 7.52019-03-27
A potential security vulnerability caused by the use of insecure (http) transactions during login has been identified with early versions of the Isaac Mizrahi Smartwatch mobile app. HP has no access to customer data as a result of this iss…
- CVE-2017-2752LOWCVSS 2.1EG 2.12019-03-27
A potential security vulnerability caused by incomplete obfuscation of application configuration information was discovered in Tommy Hilfiger TH24/7 Android app versions 2.0.0.11, 2.0.1.14, 2.1.0.16, and 2.2.0.19. HP has no access to custo…
- CVE-2017-8227CRITICALCVSS 9.8EG 9.82019-07-03
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interface provided by the device. However, if the same brute forc…
- CVE-2018-0110HIGHCVSS 8.1EG 8.12018-01-18
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to access the remote support account even after it has been disabled via the web application. The vulnerability is due to a design flaw in Cisco W…
- CVE-2018-0353HIGHCVSS 7.5EG 7.52018-06-07
A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and bypass security protections. The vulnerabi…
- CVE-2018-4863MEDIUMCVSS 5.5EG 5.52018-04-05
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.
Map vulnerabilities like CWE-254 to your infrastructure
EchelonGraph correlates every CVE — across CWE-254 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →