Vulnerabilities (CVE)

Filtered by CWE-284
Total 3634 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-1399 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
CVE-2014-1398 2 Entity Api Project, Fedoraproject 2 Entity Api, Fedora 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
CVE-2014-125054 1 Reddit-on-rails Project 1 Reddit-on-rails 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
A vulnerability classified as critical was found in koroket RedditOnRails. This vulnerability affects unknown code of the component Vote Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The patch is identified as 7f3c7407d95d532fcc342b00d68d0ea09ca71030. It is recommended to apply a patch to fix this issue. VDB-217594 is the identifier assigned to this vulnerability.
CVE-2014-10059 1 Qualcomm 14 Mdm9615, Mdm9615 Firmware, Mdm9625 and 11 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, SD 210/SD 212/SD 205, SD 400, and SD 800, improper access control on ATCMD service allows third party services to access without user knowledge.
CVE-2014-10053 1 Qualcomm 54 Mdm9206, Mdm9206 Firmware, Mdm9650 and 51 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 615/16/SD 415, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, data access is not properly validated in the Widevine secure application.
CVE-2014-10050 1 Qualcomm 12 Msm8917, Msm8917 Firmware, Msm8939 and 9 more 2024-11-21 10.0 HIGH 9.8 CRITICAL
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MSM8996, MSM8939, MSM8976, MSM8917, SDM845, and SDM660, access control collision vulnerability when accessing the replay protected memory block.
CVE-2014-0881 1 Ibm 2 Flex System X222, Integrated Management Module Firmware 2024-11-21 5.8 MEDIUM 7.4 HIGH
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.
CVE-2013-6739 1 Ibm 1 Spss Modeler 2024-11-21 5.5 MEDIUM 5.4 MEDIUM
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.
CVE-2013-6272 1 Google 1 Android 2024-11-21 6.8 MEDIUM 7.8 HIGH
The NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass intended access restrictions and consequently make phone calls to arbitrary numbers, send mmi or ussd codes, or hangup ongoing calls via a crafted application.
CVE-2013-5654 1 Yingzhipython Project 1 Yingzhipython 2024-11-21 9.4 HIGH 9.1 CRITICAL
Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
CVE-2013-2972 1 Ibm 1 Websphere Cast Iron Cloud Integration 2024-11-21 7.8 HIGH 7.5 HIGH
IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors. IBM X-Force ID: 83868.
CVE-2011-4181 1 Opensuse 1 Open Build Service 2024-11-21 5.0 MEDIUM 7.5 HIGH
A vulnerability in open build service allows remote attackers to gain access to source files even though source access is disabled. Affected releases are SUSE open build service up to and including version 2.1.15 (for 2.1) and before version 2.3.
CVE-2011-1762 1 Wordpress 1 Wordpress 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
CVE-2009-5151 1 Absolute 1 Computrace Agent 2024-11-21 7.2 HIGH 6.7 MEDIUM
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.
CVE-2009-5150 1 Absolute 1 Computrace Agent 2024-11-21 7.2 HIGH 6.7 MEDIUM
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.
CVE-2024-33027 1 Qualcomm 180 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 177 more 2024-11-20 N/A 8.4 HIGH
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
CVE-2024-39609 1 Intel 2 Server Board M70klp2sb, Server Board M70klp2sb Firmware 2024-11-19 N/A 7.5 HIGH
Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2024-11211 1 Eyoucms 1 Eyoucms 2024-11-19 5.8 MEDIUM 4.7 MEDIUM
A vulnerability classified as critical has been found in EyouCMS up to 1.6.7. Affected is an unknown function of the component Website Logo Handler. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2021-3987 1 Janeczku 1 Calibre-web 2024-11-19 N/A 4.3 MEDIUM
An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users.
CVE-2024-11214 1 Mayurik 1 Best Employee Management System 2024-11-19 5.8 MEDIUM 4.7 MEDIUM
A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher disclosure contains confusing vulnerability classes.