Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2017-06-13 CVE-2015-9024 Improper Access Control vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
local
low complexity
google CWE-284
5.5
2017-06-13 CVE-2015-9021 Improper Access Control vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
local
low complexity
google CWE-284
5.5
2017-06-13 CVE-2014-9961 Improper Access Control vulnerability in Google Android
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.
local
low complexity
google CWE-284
7.8
2017-06-09 CVE-2016-7833 Improper Access Control vulnerability in Cybozu Dezie
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.
network
low complexity
cybozu CWE-284
7.5
2017-06-09 CVE-2016-7824 Improper Access Control vulnerability in Buffalotech Wnc01Wh Firmware 1.0.0.8
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors.
network
low complexity
buffalotech CWE-284
8.8
2017-06-09 CVE-2016-7811 Improper Access Control vulnerability in Corega Cg-Wlr300Nx Firmware 1.20
Corega CG-WLR300NX firmware Ver.
low complexity
corega CWE-284
8.8
2017-06-09 CVE-2016-7807 Improper Access Control vulnerability in Iodata Wfs-Sr01 Firmware 1.10
I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors.
network
low complexity
iodata CWE-284
7.5
2017-06-09 CVE-2016-7801 Improper Access Control vulnerability in Cybozu Garoon
Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.
network
low complexity
cybozu CWE-284
4.3
2017-06-09 CVE-2016-4910 Improper Access Control vulnerability in Cybozu Garoon
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.
network
low complexity
cybozu CWE-284
4.3
2017-06-09 CVE-2016-4908 Improper Access Control vulnerability in Cybozu Garoon
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.
network
low complexity
cybozu CWE-284
4.3