CWE-264
1,426 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 3 of 29
- CVE-2013-7202HIGHCVSS 8.1EG 8.12018-04-27
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
- CVE-2013-7432HIGHCVSS 7.5EG 7.52017-08-29
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
- CVE-2014-0073CRITICALCVSS 9.8EG 9.82017-10-30
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callb…
- CVE-2014-0087HIGHCVSS 8.8EG 8.82018-01-11
The check_privileges method in vmdb/app/controllers/application_controller.rb in ManageIQ, as used in Red Hat CloudForms Management Engine (CFME), allows remote authenticated users to bypass authorization and gain privileges by leveraging …
- CVE-2014-0229MEDIUMCVSS 6.5EG 6.52017-03-23
Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshNamenodes, (2) deleteBlockPool, and (3) shutdownDatanode HDFS admin commands, which allows …
- CVE-2014-10054CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, QCA6174A, QCA6574AU, QCA9377, QCA9379, SD 210/SD…
- CVE-2014-10057CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 435, SD 617, SD 625, and Snapdragon_High_Med_2016, bi…
- CVE-2014-10058HIGHCVSS 7.5EG 7.52018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD 430, SD 435, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 845, and Snapdragon_High_Med_2016, unaut…
- CVE-2014-10070HIGHCVSS 7.8EG 7.82018-02-27
zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical condit…
- CVE-2014-1226HIGHCVSS 7.8EG 7.82018-04-06
The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
- CVE-2014-1845HIGHCVSS 7.8EG 7.82018-04-27
An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.
- CVE-2014-1846HIGHCVSS 7.8EG 7.82018-04-27
Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
- CVE-2014-1889MEDIUMCVSS 6.5EG 6.52018-04-10
The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups by leveraging a missing permissions check.
- CVE-2014-1946HIGHCVSS 8.8EG 8.82018-04-10
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.p…
- CVE-2014-2071HIGHCVSS 7.1EG 7.12018-01-08
Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain priv…
- CVE-2014-2079MEDIUMCVSS 5.5EG 5.52018-07-16
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
- CVE-2014-2532MEDIUMCVSS 4.2EG 4.92014-03-18
sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
- CVE-2014-2552CRITICALCVSS 9.8EG 9.82018-04-27
Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.
- CVE-2014-3222HIGHCVSS 7.0EG 7.02017-04-02
In Huawei eSpace Meeting with software V100R001C03SPC201 and the earlier versions, attackers that obtain the permissions assigned to common users can elevate privileges to access and set specific key resources.
- CVE-2014-3752MEDIUMCVSS 6.7EG 6.72018-02-01
The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call.
- CVE-2014-4919MEDIUMCVSS 5.4EG 5.42018-01-19
OXID eShop Professional Edition before 4.7.13 and 4.8.x before 4.8.7, Enterprise Edition before 5.0.13 and 5.1.x before 5.1.7, and Community Edition before 4.7.13 and 4.8.x before 4.8.7 allow remote attackers to assign users to arbitrary d…
- CVE-2014-5040MEDIUMCVSS 6.8EG 6.82016-01-05
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1) access key credentials by leveraging knowledge of a key I…
- CVE-2014-5070HIGHCVSS 8.8EG 8.82018-01-11
Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page.
- CVE-2014-5415CRITICALCVSS 9.1EG 9.12016-10-05
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3…
- CVE-2014-5443HIGHCVSS 7.8EG 7.82018-03-19
Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.
- CVE-2014-6276MEDIUMCVSS 4.3EG 4.32016-04-13
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
- CVE-2014-7272HIGHCVSS 7.8EG 7.82018-03-08
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitati…
- CVE-2014-7279CRITICALCVSS 9.8EG 9.82017-03-23
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
- CVE-2014-7851HIGHCVSS 7.5EG 7.52017-10-16
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their sessi…
- CVE-2014-7862CRITICALCVSS 9.8EG 9.82018-01-04
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
- CVE-2014-7920CRITICALCVSS 9.8EG 9.82017-04-13
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.
- CVE-2014-7921CRITICALCVSS 9.8EG 9.82017-04-13
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.
- CVE-2014-8156HIGHCVSS 7.8EG 7.82017-09-26
The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd…
- CVE-2014-8421HIGHCVSS 7.5EG 7.52018-04-12
Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by leveraging SSH access and incorrect ownership of (1) ConfigureCoreFile.sh, (2) Traceroute.sh…
- CVE-2014-8428CRITICALCVSS 9.8EG 9.82017-08-28
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
- CVE-2014-8540MEDIUMCVSS 6.5EG 6.52018-01-05
The groups API in GitLab 6.x and 7.x before 7.4.3 allows remote authenticated guest users to modify ownership of arbitrary groups by leveraging improper permission checks.
- CVE-2014-8571LOWCVSS 3.3EG 3.32017-04-02
Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01B508SP02; EDGE-C00 V100R001C92B508SP02 a…
- CVE-2014-8708CRITICALCVSS 9.8EG 9.82017-03-17
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
- CVE-2014-9262HIGHCVSS 8.2EG 8.22017-08-07
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
- CVE-2014-9503MEDIUMCVSS 6.5EG 6.52018-02-01
The Discussions sub module in the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal allows remote authenticated users with "access content" permissions to modify arbitrary nodes by leveraging improper access checks on unspecified ajax …
- CVE-2014-9610MEDIUMCVSS 5.3EG 5.32017-09-19
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user/quarantine_disable.php.
- CVE-2014-9695HIGHCVSS 8.8EG 8.82017-04-02
The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions could allow a non-super-domain user who accesses HMM through SNMPv3 to perform operations on a server as a super-domain user.
- CVE-2014-9696HIGHCVSS 8.8EG 8.82017-04-02
The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions allows the operator to modify the user configuration of iMana through privilege escalation.
- CVE-2014-9768HIGHCVSS 8.8EG 8.82016-03-18
IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuratio…
- CVE-2014-9770LOWCVSS 3.3EG 3.32016-04-20
tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive information by reading these files.
- CVE-2014-9779HIGHCVSS 7.8EG 7.82016-07-11
arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices allows attackers to obtain sensitive information from kernel memory via a crafted offset, aka Android internal bug 2859834…
- CVE-2014-9780HIGHCVSS 7.8EG 7.82016-07-11
drivers/video/msm/mdss/mdp3_ctrl.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5, 5X, and 6P devices does not validate start and length values, which allows attackers to gain privileges via a crafted application, aka A…
- CVE-2014-9782HIGHCVSS 7.8EG 7.82016-07-11
drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices does not validate direction and step parameters, which allows attackers to gain pri…
- CVE-2014-9783HIGHCVSS 7.8EG 7.82016-07-11
drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices does not validate certain values, which allows attackers to gain privileges via a crafted applicati…
- CVE-2014-9785HIGHCVSS 7.8EG 7.82016-07-11
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-07-05 on Nexus 7 (2013) devices does not validate addresses before copying data, which allows attackers to gain privileges via a crafted application, aka Android inte…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →