Vulnerabilities > Improper Access Control

DATE CVE VULNERABILITY TITLE RISK
2016-06-13 CVE-2016-4911 Improper Access Control vulnerability in Keystone Openstack Identity 9.0.0.0
The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.
network
low complexity
keystone CWE-284
4.3
2016-06-13 CVE-2016-1543 Improper Access Control vulnerability in BMC Bladelogic Server Automation Console
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.
network
low complexity
bmc CWE-284
7.5
2016-06-13 CVE-2016-2831 Improper Access Control vulnerability in multiple products
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.
network
low complexity
canonical mozilla debian opensuse CWE-284
8.8
2016-06-13 CVE-2016-2829 Improper Access Control vulnerability in multiple products
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
network
low complexity
canonical mozilla opensuse CWE-284
6.5
2016-06-13 CVE-2016-2825 Improper Access Control vulnerability in multiple products
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
network
low complexity
canonical opensuse mozilla CWE-284
6.5
2016-06-13 CVE-2016-2822 Improper Access Control vulnerability in multiple products
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
network
low complexity
debian mozilla canonical opensuse CWE-284
6.5
2016-06-10 CVE-2016-2785 Improper Access Control vulnerability in Puppet Puppet, Puppet Agent and Puppet Server
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.
network
low complexity
puppet CWE-284
critical
9.8
2016-06-10 CVE-2016-4524 Improper Access Control vulnerability in ABB Pcm600 2.6
ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.
local
low complexity
abb CWE-284
6.5
2016-06-10 CVE-2016-4495 Improper Access Control vulnerability in KMC Controls Bac-5051E Firmware
KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.
network
low complexity
kmc-controls CWE-284
5.3
2016-06-09 CVE-2016-2150 Improper Access Control vulnerability in multiple products
SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.
local
low complexity
redhat opensuse debian spice-project CWE-284
7.1