Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2015-3653 Improper Access Control vulnerability in Arubanetworks Clearpass
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain privileges by leveraging incorrect permission checking.
network
low complexity
arubanetworks CWE-284
7.2
2017-08-28 CVE-2014-9513 Improper Access Control vulnerability in Debian Xbindkeys-Config 0.1.32
Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.
network
low complexity
debian CWE-284
critical
9.8
2017-08-28 CVE-2014-8168 Improper Access Control vulnerability in Redhat Satellite 6.0
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
local
low complexity
redhat CWE-284
6.1
2017-08-24 CVE-2015-5293 Improper Access Control vulnerability in Redhat Enterprise Virtualization Manager
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which might allow remote attackers to communicate with a system designated to be unreachable.
network
high complexity
redhat CWE-284
5.9
2017-08-18 CVE-2016-10382 Improper Access Control vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.
network
low complexity
google CWE-284
critical
9.8
2017-08-18 CVE-2015-9064 Improper Access Control vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request before NAS security has been activated.
network
low complexity
google CWE-284
critical
9.8
2017-08-18 CVE-2015-9047 Improper Access Control vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.
network
low complexity
google CWE-284
critical
9.8
2017-08-18 CVE-2015-9040 Improper Access Control vulnerability in Google Android
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.
network
low complexity
google CWE-284
critical
9.8
2017-08-09 CVE-2015-2687 Improper Access Control vulnerability in Openstack Compute
OpenStack Compute (nova) Icehouse, Juno and Havana when live migration fails allows local users to access VM volumes that they would normally not have permissions for.
local
high complexity
openstack CWE-284
4.7
2017-08-07 CVE-2014-9831 Improper Access Control vulnerability in Imagemagick
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.
network
low complexity
imagemagick CWE-284
8.8