CVEbaza.plSłownik CWECWE-264
Common Weakness Enumeration

CWE-264

CVE: 5495
Podatności CVE z CWE-264 (5495)
10.0
CVSS
CRITICAL
CVE-2016-8363

W wielu seriach urządzeń sieciowych Moxa (access pointy, routery przemysłowe) odkryto możliwość wykonania dowolnych poleceń systemu operacyjnego przez użytkownika. Podatność uzyskała maksymalny wynik CVSS 10.0, co czyni ją krytycznym zagrożeniem dla infrastruktury przemysłowej i sieci OT.

pub. 2017-02-13
10.0
CVSS
CRITICAL
CVE-2016-7457

VMware vRealize Operations (vROps) w wersjach 6.x przed 6.4.0 zawiera podatność umożliwiającą uwierzytelnionym zdalnym użytkownikom uzyskanie wyższych uprawnień lub zatrzymanie i usunięcie maszyn wirtualnych. Krytyczny poziom zagrożenia (CVSS 10.0) wynika z braku wymagań dotyczących interakcji użytkownika i możliwości pełnego wpływu na poufność, integralność oraz dostępność środowiska.

pub. 2016-12-29
10.0
CVSS
CRITICAL
CVE-2015-7425

Komponent Data Protection w interfejsie VMware vSphere GUI produktów IBM Tivoli Storage Manager for Virtual Environments oraz Tivoli Storage FlashCopy Manager for VMware umożliwia zdalnym atakującym uzyskanie uprawnień administracyjnych. Podatność otrzymała maksymalny wynik CVSS 10.0 i nie wymaga żadnego uwierzytelnienia ani interakcji użytkownika.

pub. 2016-02-21
10.0
CVSS
CRITICAL
CVE-2015-8267

Podatność w bibliotece PasswordReset.dll umożliwia zdalnym atakującym zresetowanie dowolnego hasła w Active Directory bez uwierzytelnienia. Krytyczna waga (CVSS 10.0) wynika z pełnej dostępności przez sieć bez jakichkolwiek wymagań uwierzytelnienia.

pub. 2015-12-24
10.0
CVSS
CRITICAL
CVE-2015-7919

SearchBlox w wersji 8.3 przed 8.3.1 pozwala nieuwierzytelnionym zdalnym atakującym na nadpisanie pliku konfiguracyjnego aplikacji. Skutkiem jest crash aplikacji i niedostępność usługi (denial of service).

pub. 2015-12-21
10.0
CVSS
HIGH
CVE-2015-7071

The File Bookmark component in Apple OS X before 10.11.2 allows attackers to bypass a sandbox protection mechanism for app scoped bookmarks via a crafted pathname.

pub. 2015-12-11
10.0
CVSS
HIGH
CVE-2015-8440

Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2015-8409 and CVE-2015-8453.

pub. 2015-12-10
10.0
CVSS
HIGH
CVE-2015-8236

Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to execute arbitrary code as root by leveraging management-plane access, aka Bug 138716.

pub. 2015-11-19
10.0
CVSS
HIGH
CVE-2015-7861

Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code by sending unspecified commands in an environment that lacks relationship-based firewalling.

pub. 2015-10-19
10.0
CVSS
HIGH
CVE-2015-7709

The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and execute arbitrary commands via a series of crafted requests involving the ARKFS_EXEC_CMD operation.

pub. 2015-10-05
10.0
CVSS
HIGH
CVE-2015-0546

EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid account name.

pub. 2015-06-17
10.0
CVSS
HIGH
CVE-2015-4032

projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors.

pub. 2015-05-29
10.0
CVSS
HIGH
CVE-2015-3435

Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE request.

pub. 2015-05-01
10.0
CVSS
HIGH
CVE-2015-3459

The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allows remote attackers to modify the pump configuration via unspecified commands.

pub. 2015-04-29
10.0
CVSS
HIGH
CVE-2015-0932

The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G devices does not require authentication for rsync sessions, which allows remote attackers to read or write to arbitrary files via TCP traffic on port 873.

pub. 2015-04-05
10.0
CVSS
HIGH
CVE-2015-2284

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling.

pub. 2015-03-24
10.0
CVSS
HIGH
CVE-2015-1498

Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3) remove a role from a user account via a removeAssigneesFromRole request, or (4) have other unspecified impact.

pub. 2015-02-16
10.0
CVSS
HIGH
CVE-2014-9353

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vectors.

pub. 2015-02-06
10.0
CVSS
HIGH
CVE-2015-1448

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4.4.4621.32 allows remote attackers to bypass authentication and perform administrative actions via unspecified vectors.

pub. 2015-02-02
10.0
CVSS
HIGH
CVE-2014-4495

The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memory segment during use of a custom cache mode, which allows attackers to bypass intended access restrictions via a crafted app.

pub. 2015-01-30
Pokazano 20 z 5495 podatności
Informacje
ID: CWE-264
Podatności: 5495
MITRE CWE ↗
← Słownik CWE