CWE-767 · 4 records
Access to Critical Private Variable via Public Method
CVEs in this class
4 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2024-36463No exploit | The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objeczabbix · zabbix · CWE-767 | High8.8 | — | 0.8% | Nov 26, 2024 |
32Monitor | CVE-2016-8380Proof of concept | The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.phoenixcontact · ilc plcs firmware · CWE-767 | High7.3 | — | 10.9% | Apr 5, 2018 |
31Monitor | CVE-2020-26868No exploit | ARC Informatique PcVue Access to Critical Private Variable via Public Methodarcinfo · pcvue · CWE-767 | High7.5 | — | 2.2% | Oct 12, 2020 |
21Monitor | CVE-2024-34162No exploit | The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users.sharp corporation · multiple mfps (multifunction printers) · CWE-767 | Medium5.3 | — | 0.8% | Nov 26, 2024 |
- CVE-2024-3646335Monitor
The implementation of atob in "Zabbix JS" allows to create a string with arbitrary content and use it to access internal properties of objec
HighCVSS 8.8No exploitEPSS 1%zabbix · zabbixNov 26, 2024
- CVE-2016-838032Monitor
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
HighCVSS 7.3Proof of conceptEPSS 11%phoenixcontact · ilc plcs firmwareApr 5, 2018
- CVE-2020-2686831Monitor
ARC Informatique PcVue Access to Critical Private Variable via Public Method
HighCVSS 7.5No exploitEPSS 2%arcinfo · pcvueOct 12, 2020
- CVE-2024-3416221Monitor
The web interface of the affected devices is designed to hide the LDAP credentials even for administrative users.
MediumCVSS 5.3No exploitEPSS 1%sharp corporation · multiple mfps (multifunction printers)Nov 26, 2024