Vulnerabilities (CVE)

Filtered by CWE-284
Total 4156 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4910 1 Cybozu 1 Garoon 2026-05-13 4.0 MEDIUM 4.3 MEDIUM
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
CVE-2016-8300 1 Oracle 1 Flexcube Private Banking 2026-05-13 3.5 LOW 5.3 MEDIUM
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data. CVSS v3.0 Base Score 5.3 (Confidentiality impacts).
CVE-2015-7263 1 Proxygen Project 1 Proxygen 2026-05-13 5.0 MEDIUM 7.5 HIGH
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass ACL checks via a crafted host value.
CVE-2016-6342 2 Elog Project, Fedoraproject 2 Elog, Fedora 2026-05-13 5.0 MEDIUM 7.5 HIGH
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
CVE-2016-5026 1 Onionshare 1 Onionshare 2026-05-13 2.1 LOW 5.5 MEDIUM
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
CVE-2015-8275 1 Eparaksts 2 Edoc-libraries, Eparakstitajs 3 2026-05-13 4.3 MEDIUM 5.5 MEDIUM
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.
CVE-2015-7265 1 Proxygen Project 1 Proxygen 2026-05-13 5.0 MEDIUM 7.5 HIGH
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijacking attacks and bypass ACL checks.
CVE-2016-5747 1 Novell 1 Edirectory 2026-05-13 5.0 MEDIUM 7.5 HIGH
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to bypass intended access restrictions by leveraging predictable cookies.
CVE-2016-8752 1 Apache 1 Atlas 2026-05-13 5.0 MEDIUM 7.5 HIGH
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URIs like /js and /img.
CVE-2015-8987 1 Mcafee 1 Agent 2026-05-13 3.5 LOW 5.3 MEDIUM
Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.
CVE-2016-9008 1 Ibm 1 Urbancode Deploy 2026-05-13 5.0 MEDIUM 7.5 HIGH
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent.
CVE-2016-8932 1 Ibm 1 Kenexa Lms 2026-05-13 6.5 MEDIUM 8.8 HIGH
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVE-2016-4800 2 Eclipse, Microsoft 2 Jetty, Windows 2026-05-13 7.5 HIGH 9.8 CRITICAL
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.
CVE-2016-9378 1 Xen 1 Xen 2026-05-13 2.1 LOW 5.5 MEDIUM
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
CVE-2016-1178 1 Appleple 1 A-blog Cms 2026-05-13 6.4 MEDIUM 6.5 MEDIUM
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
CVE-2016-6255 2 Debian, Libupnp Project 2 Debian Linux, Libupnp 2026-05-13 5.0 MEDIUM 7.5 HIGH
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registered handler.
CVE-2013-4246 1 Apache 1 Subversion 2026-05-13 6.5 MEDIUM 8.8 HIGH
libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.
CVE-2015-7898 1 Samsung 2 Galaxy S6, Samsung Mobile 2026-05-13 2.1 LOW 5.5 MEDIUM
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
CVE-2015-3302 1 Thecartpress 1 Thecartpress Ecommerce Shopping Cart 2026-05-13 5.0 MEDIUM 7.5 HIGH
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote attackers to obtain sensitive order detail information by leveraging a "broken authentication mechanism."
CVE-2016-2787 2 Puppet, Puppetlabs 2 Puppet Enterprise, Puppet Enterprise 2026-05-13 5.0 MEDIUM 5.3 MEDIUM
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors.