Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2014-9830 Improper Access Control vulnerability in Imagemagick
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2014-9828 Improper Access Control vulnerability in Imagemagick
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2014-9827 Improper Access Control vulnerability in Imagemagick
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.
network
low complexity
imagemagick CWE-284
8.8
2017-08-07 CVE-2015-7887 Improper Access Control vulnerability in Netapp Snapcenter Server 1.0
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
network
low complexity
netapp CWE-284
8.1
2017-06-29 CVE-2016-10042 Improper Access Control vulnerability in Arcadyan Swisscom Internet-Box Firmware
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.
network
low complexity
arcadyan CWE-284
7.5
2017-06-27 CVE-2016-6342 Improper Access Control vulnerability in multiple products
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
network
low complexity
fedoraproject elog-project CWE-284
7.5
2017-06-27 CVE-2016-5414 Improper Access Control vulnerability in Freeipa 4.4.0
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
network
low complexity
freeipa CWE-284
7.5
2017-06-27 CVE-2016-4383 Improper Access Control vulnerability in HP Helion Openstack Glance
The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.
network
low complexity
hp CWE-284
8.4
2017-06-27 CVE-2015-8697 Improper Access Control vulnerability in Stalin Project Stalin 0.115
stalin 0.11-5 allows local users to write to arbitrary files.
local
low complexity
stalin-project CWE-284
5.5
2017-06-27 CVE-2015-7898 Improper Access Control vulnerability in Samsung Mobile
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
local
low complexity
samsung CWE-284
5.5