Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2019-02-15 CVE-2013-5654 Improper Access Control vulnerability in Yingzhipython Project Yingzhipython 1.9
Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
network
low complexity
yingzhipython-project CWE-284
critical
9.1
2019-01-24 CVE-2019-1647 Improper Access Control vulnerability in Cisco Sd-Wan and Vsmart Controller
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, adjacent attacker to bypass authentication and have direct unauthorized access to other vSmart containers.
low complexity
cisco CWE-284
8.0
2018-11-16 CVE-2018-7362 Improper Access Control vulnerability in ZTE Zxhn F670 Firmware
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by improper access control vulnerability, which may allows an unauthorized user to perform unauthorized operations on the router.
network
low complexity
zte CWE-284
8.8
2018-10-30 CVE-2018-17931 Improper Access Control vulnerability in Vecna VGO Firmware 3.0.3.52164/3.0.3.53662
If an attacker has physical access to the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662.
low complexity
vecna CWE-284
6.8
2018-10-29 CVE-2018-17908 Improper Access Control vulnerability in Advantech Webaccess
WebAccess Versions 8.3.2 and prior.
local
low complexity
advantech CWE-284
7.8
2018-08-20 CVE-2016-7048 Improper Access Control vulnerability in Postgresql
The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.
network
high complexity
postgresql CWE-284
8.1
2018-07-13 CVE-2016-6543 Improper Access Control vulnerability in Ieasytec Itrack Easy
A captured MAC/device ID of an iTrack Easy can be registered under multiple user accounts allowing access to getgps GPS data, which can allow unauthenticated parties to track the device.
network
high complexity
ieasytec CWE-284
5.9
2018-07-11 CVE-2013-2972 Improper Access Control vulnerability in IBM Websphere Cast Iron Cloud Integration 6.0.0.0/6.1.0.0/6.3.0.0
IBM WebSphere Cast Iron 6.3 allows remote attackers to bypass intended access restrictions via unspecified vectors.
network
low complexity
ibm CWE-284
7.5
2018-06-11 CVE-2016-9905 Improper Access Control vulnerability in multiple products
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents.
network
low complexity
redhat debian mozilla CWE-284
8.8
2018-05-11 CVE-2009-5151 Improper Access Control vulnerability in Absolute Computrace Agent 70.785
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS.
local
low complexity
absolute CWE-284
6.7