VulnSea

CWE-284

CVEs classified under CWE-284, newest first.

1097 CVEsRSS

CVE-2023-20579Medium· 6.0
2y ago

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

▾ Sunlitamd · ryzen_7_5700g_firmwareEPSS 0.16%via NVD
CVE-2024-23681High· 8.2
2y ago

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary

Artemis Java Test Sandbox versions before 1.11.2 are vulnerable to a sandbox escape when an attacker loads untrusted libraries using System.load or System.loadLibrary. An attacker can abuse this issue to execute arbitrary Java when a vic…

▾ Twilightls1intum · artemis_java_test_sandboxEPSS 0.34%via NVD
CVE-2023-51384Medium· 5.5
2y ago

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first k…

▾ Sunlitopenbsd · opensshEPSS 0.43%via NVD
CVE-2023-43901High· 7.5
2y ago

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.

▾ Twilightemudhra · emsignerEPSS 0.47%via NVD
CVE-2023-28531Critical· 9.8
3y ago

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

▾ Midnightopenbsd · opensshEPSS 2.3%via NVD
CVE-2021-4037Medium· 4.4
4y ago

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permis…

A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permis…

▾ Sunlitlinux · linux_kernelEPSS 0.31%via NVD
CVE-2020-1754Medium· 4.3
4y ago

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, users viewing the grade history report without the 'access all groups' capability were not restricted to viewing grades of users within their own groups.

▾ Sunlitmoodle · moodleEPSS 0.64%via NVD
CVE-2020-3565Medium· 5.8
5y ago

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices …

A vulnerability in the TCP Intercept functionality of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Access Control Policies (including Geolocation) and Service Polices …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.94%via NVD
CVE-2020-3564Medium· 5.3
5y ago

A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection

A vulnerability in the FTP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass FTP inspection. The vulnerabilit…

▾ Sunlitcisco · adaptive_security_applianceEPSS 1.3%via NVD
CVE-2020-3253Medium· 6.7
6y ago

A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled

A vulnerability in the support tunnel feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to access the shell of an affected device even though expert mode is disabled. The vulnerability …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.30%via NVD
CVE-2020-3186Medium· 5.3
6y ago

A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system

A vulnerability in the management access list configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured management interface access list on an affected system. T…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.4%via NVD
CVE-2019-12627High· 7.5
7y ago

A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data

A vulnerability in the application policy configuration of the Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data. The vulnerability is due to …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.2%via NVD
CVE-2019-11634Critical· 9.8CISA KEV
7y ago

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

Citrix Workspace App before 1904 for Windows has Incorrect Access Control.

▾ Hadalcitrix · receiverEPSS 8.0%via NVD
CVE-2019-1695Medium· 6.5
7y ago

A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an aff…

A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an aff…

▾ Sunlitcisco · adaptive_security_appliance_softwareEPSS 0.71%via NVD
CVE-2018-15398Medium· 4.0
7y ago

A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL)…

A vulnerability in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control list (ACL)…

▾ Sunlitcisco · adaptive_security_appliance_softwareEPSS 1.9%via NVD
CVE-2012-4681Critical· 9.8CISA KEVPoC
14y ago

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) usi…

Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow remote attackers to execute arbitrary code via a crafted applet that bypasses SecurityManager restrictions by (1) usi…

▾ Hadaloracle · jdkEPSS 99%via NVD
CVE-2012-1723Critical· 9.8CISA KEVPoC
14y ago

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidential…

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidential…

▾ Hadaloracle · jdkEPSS 94%via NVD
CWE-284 vulnerabilities (CVEs) — page 37 · VulnSea