CWE-284— Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.— MITRE CWE catalog
7,278 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-284page 2 of 146
- CVE-2014-3519MEDIUMCVSS 6.5EG 6.52018-02-01
The open_by_handle_at function in vzkernel before 042stab090.5 in the OpenVZ modification for the Linux kernel 2.6.32, when using simfs, might allow local container users with CAP_DAC_READ_SEARCH capability to bypass an intended container …
- CVE-2014-3624CRITICALCVSS 9.8EG 9.82017-10-30
Apache Traffic Server 5.1.x before 5.1.1 allows remote attackers to bypass access restrictions by leveraging failure to properly tunnel remap requests using CONNECT.
- CVE-2014-3928CRITICALCVSS 9.8EG 9.82017-04-03
Cougar-LG stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain credentials.
- CVE-2014-3929HIGHCVSS 7.5EG 7.52017-04-03
The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control, which might allow remote attackers to obtain private ssh keys.
- CVE-2014-3930HIGHCVSS 7.5EG 7.52017-04-03
lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows remote attackers to obtain IP addresses and other unspecified router credentials.
- CVE-2014-4707HIGHCVSS 8.8EG 8.82017-04-02
Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SP…
- CVE-2014-5208HIGHCVSS v2 7.5EG 7.52014-12-22
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, and Exaopc through R3.72.10, does not require authentication, which allows remote attackers…
- CVE-2014-5279HIGHCVSS 8.8EG 8.82018-02-06
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
- CVE-2014-6078MEDIUMCVSS v2 5.0EG 5.02014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to…
- CVE-2014-6109MEDIUMCVSS 5.3EG 5.32018-04-20
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated users to bypass intended access restricti…
- CVE-2014-6110LOWCVSS v2 2.1EG 2.12014-11-18
IBM Security Identity Manager 6.x before 6.0.0.3 IF14 does not properly perform logout actions, which allows remote attackers to access sessions by leveraging an unattended workstation.
- CVE-2014-6195LOWCVSS v2 1.9EG 1.92015-02-14
The (1) Java GUI and (2) Web GUI components in the IBM Tivoli Storage Manager (TSM) Backup-Archive client 5.4 and 5.5 before 5.5.4.4 on AIX, Linux, and Solaris; 5.4.x and 5.5.x on Windows and z/OS; 6.1 before 6.1.5.7 on z/OS; 6.1 and 6.2 b…
- CVE-2014-6319MEDIUMCVSS v2 5.0EG 5.02014-12-11
Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified…
- CVE-2014-6625HIGHCVSS v2 9.0EG 9.02014-11-19
The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecified vectors.
- CVE-2014-6626HIGHCVSS v2 10.0EG 10.02014-11-19
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown v…
- CVE-2014-6627HIGHCVSS v2 9.0EG 9.02014-11-19
Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2014-5342.
- CVE-2014-7905MEDIUMCVSS v2 5.0EG 5.02014-11-19
Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, which allows remote attackers to bypass intended access restrictions via a crafted web site.
- CVE-2014-8168MEDIUMCVSS 6.1EG 6.12017-08-28
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
- CVE-2014-8177MEDIUMCVSS 6.5EG 6.52016-06-07
The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass the max_meta_count constraint via multiple crafted requests which exceed the limit when co…
- CVE-2014-8183HIGHCVSS 7.4EG 7.42019-08-01
It was found that foreman, versions 1.x.x before 1.15.6, in Satellite 6 did not properly enforce access controls on certain resources. An attacker with access to the API and knowledge of the resource name can access resources in other orga…
- CVE-2014-8362CRITICALCVSS 9.8EG 9.82017-01-23
Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enabled interface.
- CVE-2014-8631MEDIUMCVSS v2 4.3EG 4.32014-12-11
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 supports native-interface passing, which allows remote attackers to bypass intended DOM object restrictions via a call to an unspecifie…
- CVE-2014-8632MEDIUMCVSS v2 4.3EG 4.32014-12-11
The structured-clone implementation in Mozilla Firefox before 34.0 and SeaMonkey before 2.31 does not properly interact with XrayWrapper property filtering, which allows remote attackers to bypass intended DOM object restrictions by levera…
- CVE-2014-8677MEDIUMCVSS 5.3EG 5.32017-08-31
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2…
- CVE-2014-8757HIGHCVSS v2 8.3EG 8.32015-02-17
LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.
- CVE-2014-8827LOWCVSS v2 2.1EG 2.12015-01-30
LoginWindow in Apple OS X before 10.10.2 does not transition to the lock-screen state immediately upon being woken from sleep, which allows physically proximate attackers to obtain sensitive information by reading the screen.
- CVE-2014-8833LOWCVSS v2 2.1EG 2.12015-01-30
SpotlightIndex in Apple OS X before 10.10.2 does not properly perform deserialization during access to a permission cache, which allows local users to read search results associated with other users' protected files via a Spotlight query.
- CVE-2014-9117MEDIUMCVSS v2 5.0EG 5.02014-12-06
MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA protection mechanism by leveraging knowledge of a CAPTCHA answer for a public_key parameter va…
- CVE-2014-9148CRITICALCVSS 9.8EG 9.82017-10-16
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
- CVE-2014-9151HIGHCVSS v2 7.5EG 7.52014-12-01
The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack on the administrative password.
- CVE-2014-9197HIGHCVSS v2 7.8EG 7.82015-01-27
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration informatio…
- CVE-2014-9388MEDIUMCVSS v2 5.0EG 5.02014-12-17
bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.
- CVE-2014-9422MEDIUMCVSS v2 6.1EG 6.12015-02-19
The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.13.x before 1.13.1 allows remote authenticated users to bypass a kadmin/* authorization che…
- CVE-2014-9489HIGHCVSS 8.8EG 8.82017-10-17
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote authenticated users to execute arbitrar…
- CVE-2014-9504HIGHCVSS 7.5EG 7.52018-02-01
The OG Subgroups module, when used with the Open Atrium module 7.x-2.x before 7.x-2.26 for Drupal, allows remote attackers to access child groups via vectors related to membership inheritance.
- CVE-2014-9513CRITICALCVSS 9.8EG 9.82017-08-28
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
- CVE-2014-9572HIGHCVSS v2 7.5EG 7.52015-01-26
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.
- CVE-2014-9648MEDIUMCVSS v2 4.3EG 4.32015-01-27
components/navigation_interception/intercept_navigation_resource_throttle.cc in Google Chrome before 40.0.2214.91 on Android does not properly restrict use of intent: URLs to open an application after navigation to a web site, which allows…
- CVE-2014-9717MEDIUMCVSS 6.1EG 6.12016-05-02
fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which allows local users to bypass intended access restrictions and navigate to filesystem locat…
- CVE-2014-9773HIGHCVSS 7.5EG 7.52016-06-13
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
- CVE-2014-9798MEDIUMCVSS 5.5EG 5.52016-07-11
platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tags addresses and aboot addresses, which allows attackers to cause a denial of service (OS o…
- CVE-2014-9827HIGHCVSS 8.8EG 8.82017-08-07
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
- CVE-2014-9828HIGHCVSS 8.8EG 8.82017-08-07
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
- CVE-2014-9830HIGHCVSS 8.8EG 8.82017-08-07
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
- CVE-2014-9831HIGHCVSS 8.8EG 8.82017-08-07
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
- CVE-2014-9865HIGHCVSS 7.8EG 7.82016-08-06
drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space input, which allows attackers to gain privileges via a crafted application, aka Android in…
- CVE-2014-9901HIGHCVSS 7.5EG 7.52016-08-05
The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cause a denial of service (device hang or reboot) via crafted frames, aka Android internal bu…
- CVE-2014-9920MEDIUMCVSS 5.9EG 5.92017-03-14
Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, a…
- CVE-2014-9961HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.
- CVE-2015-0008HIGHCVSS v2 8.3EG 8.32015-02-11
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authen…
Map vulnerabilities like CWE-284 to your infrastructure
EchelonGraph correlates every CVE — across CWE-284 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →