Vulnerabilities (CVE)

Filtered by CWE-264
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-0850 1 Google 1 Android 2016-04-21 5.8 MEDIUM 8.8 HIGH
The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to bypass intended pairing restrictions via a crafted device, aka internal bug 26551752.
CVE-2016-0847 1 Google 1 Android 2016-04-21 7.2 HIGH 8.4 HIGH
The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephone number of a call via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26864502.
CVE-2016-2410 1 Google 1 Android 2016-04-20 6.9 MEDIUM 7.4 HIGH
A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control over a service that can call this driver, aka internal bug 26291677.
CVE-2016-0844 1 Google 1 Android 2016-04-20 7.2 HIGH 8.4 HIGH
The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privileges via a crafted application, aka internal bug 26324307.
CVE-2016-0843 1 Google 1 Android 2016-04-20 7.2 HIGH 8.4 HIGH
The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197.
CVE-2016-0735 1 Apache 1 Ranger 2016-04-19 6.5 MEDIUM 8.8 HIGH
Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishandling of a resource-level exclude policy.
CVE-2016-1235 2 Debian, Oar Project 2 Debian Linux, Oar 2016-04-14 9.0 HIGH 8.8 HIGH
The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via vectors related to OpenSSH options.
CVE-2016-2171 1 Apache 1 Jetspeed 2016-04-14 6.4 MEDIUM 7.5 HIGH
The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.
CVE-2016-3187 1 Prepopulate Project 1 Prepopulate 2016-04-14 7.5 HIGH 7.3 HIGH
The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspecified impact, via a base64-encoded pp parameter.
CVE-2016-3188 1 Prepopulate Project 1 Prepopulate 2016-04-14 7.5 HIGH 7.3 HIGH
The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions, (2) container, (3) token, (4) password, (5) password_confirm, (6) text_format, or (7) markup field type, and consequently have unspecified impact, via unspecified vectors.
CVE-2016-2405 1 Huawei 2 Policy Center, Policy Center Firmware 2016-04-14 9.0 HIGH 8.8 HIGH
Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cause a denial of service (system crash) via a crafted URL.
CVE-2016-2393 1 Lenovo 2 Fingerprint Manager, Touch Fingerprint 2016-04-14 7.2 HIGH 7.8 HIGH
Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.
CVE-2015-5329 1 Redhat 1 Openstack 2016-04-13 7.5 HIGH 7.3 HIGH
The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured RabbitMQ credentials, which makes it easier for remote attackers to obtain access to services in deployed overclouds by leveraging knowledge of the default credentials.
CVE-2015-0266 1 Apache 1 Ranger 2016-04-13 6.5 MEDIUM 7.1 HIGH
The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to module URLs.
CVE-2016-3169 2 Debian, Drupal 2 Debian Linux, Drupal 2016-04-13 6.8 MEDIUM 8.1 HIGH
The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.
CVE-2014-9768 1 Ibm 1 Tivoli Netview Access Services 2016-03-21 9.0 HIGH 8.8 HIGH
** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability.
CVE-2016-2281 1 Abb 1 Panel Builder 800 2016-03-21 6.0 MEDIUM 7.2 HIGH
Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
CVE-2016-0806 1 Google 1 Android 2016-03-16 7.2 HIGH 8.4 HIGH
The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453.
CVE-2016-0810 1 Google 1 Android 2016-03-14 6.9 MEDIUM 7.8 HIGH
media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requirements, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25781119.
CVE-2016-0809 1 Google 1 Android 2016-03-14 8.3 HIGH 8.8 HIGH
Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the local physical environment during execution of a crafted application, aka internal bug 25753768.
CVE-2016-0805 1 Google 1 Android 2016-03-11 7.2 HIGH 8.4 HIGH
The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.
CVE-2016-0807 1 Google 1 Android 2016-03-11 7.2 HIGH 8.4 HIGH
The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.
CVE-2016-1322 1 Cisco 1 Spark 2016-03-01 5.0 MEDIUM 7.5 HIGH
The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584.
CVE-2016-1233 1 Debian 2 Debian Linux, Fuse 2016-02-01 7.2 HIGH 7.8 HIGH
An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world-writable permissions for the /dev/cuse character device, which allows local users to gain privileges via a character device in /dev, related to an ioctl.
CVE-2016-0852 1 Advantech 1 Webaccess 2016-01-21 5.0 MEDIUM 7.5 HIGH
Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.
CVE-2015-8279 1 Samsung 1 Web Viewer 2016-01-20 5.0 MEDIUM 8.6 HIGH
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.
CVE-2015-8333 1 Huawei 1 Vcn500 2016-01-12 5.5 MEDIUM 7.1 HIGH
The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP address of the media server via crafted packets.
CVE-2015-8754 1 Acquia 1 Mollom 2016-01-12 5.0 MEDIUM 7.5 HIGH
The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist via unspecified vectors.
CVE-2015-6980 1 Apple 1 Mac Os X 2016-01-12 7.2 HIGH 7.8 HIGH
Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecified vectors.
CVE-2015-7430 1 Apache 1 Hadoop 2016-01-07 4.6 MEDIUM 8.4 HIGH
The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to read or write to arbitrary GPFS data via unspecified vectors.
CVE-2015-7788 1 Asus 2 Wl-330nul, Wl-330nul Firmware 2015-12-30 5.8 MEDIUM 7.3 HIGH
ASUS Japan WL-330NUL devices with firmware before 3.0.0.42 allow remote attackers to execute arbitrary commands via unspecified vectors.