Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2016-06-23 CVE-2016-0914 Improper Access Control vulnerability in EMC products
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated users to bypass intended access restrictions and execute arbitrary IAPI/IDQL commands via the IAPI/IDQL interface.
network
low complexity
emc CWE-284
6.3
2016-06-19 CVE-2016-4811 Improper Access Control vulnerability in Ntt-Bp Japan Connected-Free Wi-Fi 1.13.0/1.15.1
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.
network
high complexity
ntt-bp CWE-284
5.6
2016-06-19 CVE-2016-0392 Improper Access Control vulnerability in IBM products
IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.
local
low complexity
ibm CWE-284
8.4
2016-06-19 CVE-2016-4813 Improper Access Control vulnerability in Netcommons 2.4.2.1
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.
network
low complexity
netcommons CWE-284
8.8
2016-06-16 CVE-2016-3226 Improper Access Control vulnerability in Microsoft Windows Server 2008 and Windows Server 2012
Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."
network
low complexity
microsoft CWE-284
6.5
2016-06-14 CVE-2016-5366 Improper Access Control vulnerability in Huawei Honor Ws851 Firmware 1.1.21.1
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.
network
low complexity
huawei CWE-284
7.5
2016-06-13 CVE-2016-3698 Improper Access Control vulnerability in multiple products
libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.
network
high complexity
redhat libndp debian canonical CWE-284
8.1
2016-06-13 CVE-2014-9773 Improper Access Control vulnerability in multiple products
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
network
low complexity
opensuse atheme CWE-284
7.5
2016-06-13 CVE-2016-5302 Improper Access Control vulnerability in Citrix Xenserver
Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.
network
low complexity
citrix CWE-284
critical
9.8
2016-06-13 CVE-2016-5104 Improper Access Control vulnerability in multiple products
The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and communicate with services on iOS devices by connecting to an IPv4 TCP socket.
network
low complexity
libimobiledevice canonical opensuse CWE-284
5.3