CWE-264 · 5 366 записей
Permissions, Privileges, and Access Controls
CVE этого класса
5 366 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
65На этой неделе | CVE-2013-6955Готовый эксплойт | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 alsynology · diskstation manager · CWE-264 | Критическая10,0 | — | 84,6 % | 9 янв. 2014 г. |
64На этой неделе | CVE-2019-1620Готовый эксплойт | Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerabilitycisco · data center network manager · CWE-264 | Критическая9,8 | — | 83,8 % | 26 июн. 2019 г. |
64На этой неделе | CVE-2016-10372Готовый эксплойт | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP porteir · d1000 modem firmware · CWE-264 | Критическая9,8 | — | 81,8 % | 16 мая 2017 г. |
64На этой неделе | CVE-2014-9583Готовый эксплойт | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and otasus · wrt firmware · CWE-264 | Критическая10,0 | — | 80,2 % | 8 янв. 2015 г. |
64На этой неделе | CVE-2009-3843Готовый эксплойт | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Критическая10,0 | — | 79,0 % | 23 нояб. 2009 г. |
64На этой неделе | CVE-2015-7709Готовый эксплойт | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authenticationarkeia · western digital arkeia · CWE-264 | Критическая10,0 | — | 79,0 % | 5 окт. 2015 г. |
63На этой неделе | CVE-2014-7862Готовый эксплойт | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create adzohocorp · desktop central · CWE-264 | Критическая9,8 | — | 81,0 % | 4 янв. 2018 г. |
63На этой неделе | CVE-1999-1011Готовый эксплойт | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, whmicrosoft · data access components · CWE-264 | Критическая10,0 | — | 77,1 % | 19 июл. 1999 г. |
62На этой неделе | CVE-2015-2794Proof of concept | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via dnnsoftware · dotnetnuke · CWE-264 | Критическая9,8 | — | 75,1 % | 6 февр. 2017 г. |
62На этой неделе | CVE-2015-2284Готовый эксплойт | userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbisolarwinds · firewall security manager · CWE-264 | Критическая10,0 | — | 73,5 % | 24 мар. 2015 г. |
62На этой неделе | CVE-2007-2815Proof of concept | The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACLmicrosoft · internet information services · CWE-264 | Критическая10,0 | — | 73,4 % | 22 мая 2007 г. |
62На этой неделе | CVE-2012-0297Готовый эксплойт | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Критическая10,0 | — | 73,0 % | 21 мая 2012 г. |
62На этой неделе | CVE-2016-3643Готовый эксплойт | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonssolarwinds · virtualization manager · CWE-264 | Высокая7,8 | KEV | 3,7 % | 17 июн. 2016 г. |
60На этой неделе | CVE-2015-7766Готовый эксплойт | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vizohocorp · manageengine opmanager · CWE-264 | Критическая9,0 | — | 80,6 % | 9 окт. 2015 г. |
60На этой неделе | CVE-2009-3068Готовый эксплойт | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers toadobe · robohelp server · CWE-264 | Критическая9,3 | — | 78,2 % | 4 сент. 2009 г. |
60На этой неделе | CVE-2016-1909Готовый эксплойт | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.fortinet · fortios · CWE-264 | Критическая9,8 | — | 71,3 % | 15 янв. 2016 г. |
60На этой неделе | CVE-2011-5010Готовый эксплойт | apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters ictekproducts · skyrouter · CWE-264 | Критическая10,0 | — | 65,7 % | 24 дек. 2011 г. |
59В плане | CVE-2014-0112Готовый эксплойт | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackersapache · struts · CWE-264 | Высокая7,5 | — | 97,9 % | 29 апр. 2014 г. |
59В плане | CVE-2010-1240Готовый эксплойт | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in tadobe · acrobat reader · CWE-264 | Критическая9,3 | — | 73,6 % | 5 апр. 2010 г. |
59В плане | CVE-2014-0514Готовый эксплойт | The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to eadobe · adobe reader · CWE-264 | Критическая9,3 | — | 72,2 % | 15 апр. 2014 г. |
59В плане | CVE-2016-6662Proof of concept | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Критическая9,8 | — | 67,7 % | 20 сент. 2016 г. |
59В плане | CVE-2012-0299Готовый эксплойт | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Критическая10,0 | — | 63,7 % | 21 мая 2012 г. |
58В плане | CVE-2017-6622Proof of concept | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass aucisco · prime collaboration provisioning · CWE-264 | Критическая9,8 | — | 62,2 % | 18 мая 2017 г. |
58В плане | CVE-2014-2321Proof of concept | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Критическая10,0 | — | 59,3 % | 11 мар. 2014 г. |
57В плане | CVE-2015-3628Готовый эксплойт | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,f5 · big-iq security · CWE-264 | Критическая9,0 | — | 69,3 % | 7 дек. 2015 г. |
- CVE-2013-695565На этой неделе
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al
КритическаяCVSS 10,0Готовый эксплойтEPSS 85 %synology · diskstation manager9 янв. 2014 г.
- CVE-2019-162064На этой неделе
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %cisco · data center network manager26 июн. 2019 г.
- CVE-2016-1037264На этой неделе
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %eir · d1000 modem firmware16 мая 2017 г.
- CVE-2014-958364На этой неделе
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot
КритическаяCVSS 10,0Готовый эксплойтEPSS 80 %asus · wrt firmware8 янв. 2015 г.
- CVE-2009-384364На этой неделе
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %hp · operations manager23 нояб. 2009 г.
- CVE-2015-770964На этой неделе
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication
КритическаяCVSS 10,0Готовый эксплойтEPSS 79 %arkeia · western digital arkeia5 окт. 2015 г.
- CVE-2014-786263На этой неделе
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad
КритическаяCVSS 9,8Готовый эксплойтEPSS 81 %zohocorp · desktop central4 янв. 2018 г.
- CVE-1999-101163На этой неделе
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh
КритическаяCVSS 10,0Готовый эксплойтEPSS 77 %microsoft · data access components19 июл. 1999 г.
- CVE-2015-279462На этой неделе
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via
КритическаяCVSS 9,8Proof of conceptEPSS 75 %dnnsoftware · dotnetnuke6 февр. 2017 г.
- CVE-2015-228462На этой неделе
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %solarwinds · firewall security manager24 мар. 2015 г.
- CVE-2007-281562На этой неделе
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL
КритическаяCVSS 10,0Proof of conceptEPSS 73 %microsoft · internet information services22 мая 2007 г.
- CVE-2012-029762На этой неделе
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
КритическаяCVSS 10,0Готовый эксплойтEPSS 73 %symantec · web gateway21 мая 2012 г.
- CVE-2016-364362На этой неделе
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 4 %solarwinds · virtualization manager17 июн. 2016 г.
- CVE-2015-776660На этой неделе
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi
КритическаяCVSS 9,0Готовый эксплойтEPSS 81 %zohocorp · manageengine opmanager9 окт. 2015 г.
- CVE-2009-306860На этой неделе
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to
КритическаяCVSS 9,3Готовый эксплойтEPSS 78 %adobe · robohelp server4 сент. 2009 г.
- CVE-2016-190960На этой неделе
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.
КритическаяCVSS 9,8Готовый эксплойтEPSS 71 %fortinet · fortios15 янв. 2016 г.
- CVE-2011-501060На этой неделе
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i
КритическаяCVSS 10,0Готовый эксплойтEPSS 66 %ctekproducts · skyrouter24 дек. 2011 г.
- CVE-2014-011259В плане
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers
ВысокаяCVSS 7,5Готовый эксплойтEPSS 98 %apache · struts29 апр. 2014 г.
- CVE-2010-124059В плане
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t
КритическаяCVSS 9,3Готовый эксплойтEPSS 74 %adobe · acrobat reader5 апр. 2010 г.
- CVE-2014-051459В плане
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e
КритическаяCVSS 9,3Готовый эксплойтEPSS 72 %adobe · adobe reader15 апр. 2014 г.
- CVE-2016-666259В плане
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
КритическаяCVSS 9,8Proof of conceptEPSS 68 %oracle · mysql20 сент. 2016 г.
- CVE-2012-029959В плане
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
КритическаяCVSS 10,0Готовый эксплойтEPSS 64 %symantec · web gateway21 мая 2012 г.
- CVE-2017-662258В плане
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au
КритическаяCVSS 9,8Proof of conceptEPSS 62 %cisco · prime collaboration provisioning18 мая 2017 г.
- CVE-2014-232158В плане
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
КритическаяCVSS 10,0Proof of conceptEPSS 59 %zte · f46011 мар. 2014 г.
- CVE-2015-362857В плане
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,
КритическаяCVSS 9,0Готовый эксплойтEPSS 69 %f5 · big-iq security7 дек. 2015 г.