CWE-264 · 5.366 kayıt
Permissions, Privileges, and Access Controls
Bu sınıftaki CVE’ler
5.366 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
65Bu hafta | CVE-2013-6955Silahlaştırılmış | webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 alsynology · diskstation manager · CWE-264 | Kritik10,0 | — | %84,6 | 9 Oca 2014 |
64Bu hafta | CVE-2019-1620Silahlaştırılmış | Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerabilitycisco · data center network manager · CWE-264 | Kritik9,8 | — | %83,8 | 26 Haz 2019 |
64Bu hafta | CVE-2016-10372Silahlaştırılmış | The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP porteir · d1000 modem firmware · CWE-264 | Kritik9,8 | — | %81,8 | 16 May 2017 |
64Bu hafta | CVE-2014-9583Silahlaştırılmış | common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and otasus · wrt firmware · CWE-264 | Kritik10,0 | — | %80,2 | 8 Oca 2015 |
64Bu hafta | CVE-2009-3843Silahlaştırılmış | HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackershp · operations manager · CWE-264 | Kritik10,0 | — | %79,0 | 23 Kas 2009 |
64Bu hafta | CVE-2015-7709Silahlaştırılmış | The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authenticationarkeia · western digital arkeia · CWE-264 | Kritik10,0 | — | %79,0 | 5 Eki 2015 |
63Bu hafta | CVE-2014-7862Silahlaştırılmış | The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create adzohocorp · desktop central · CWE-264 | Kritik9,8 | — | %81,0 | 4 Oca 2018 |
63Bu hafta | CVE-1999-1011Silahlaştırılmış | The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, whmicrosoft · data access components · CWE-264 | Kritik10,0 | — | %77,1 | 19 Tem 1999 |
62Bu hafta | CVE-2015-2794Kavram kanıtı | The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via dnnsoftware · dotnetnuke · CWE-264 | Kritik9,8 | — | %75,1 | 6 Şub 2017 |
62Bu hafta | CVE-2015-2284Silahlaştırılmış | userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbisolarwinds · firewall security manager · CWE-264 | Kritik10,0 | — | %73,5 | 24 Mar 2015 |
62Bu hafta | CVE-2007-2815Kavram kanıtı | The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACLmicrosoft · internet information services · CWE-264 | Kritik10,0 | — | %73,4 | 22 May 2007 |
62Bu hafta | CVE-2012-0297Silahlaştırılmış | The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote symantec · web gateway · CWE-264 | Kritik10,0 | — | %73,0 | 21 May 2012 |
62Bu hafta | CVE-2016-3643Silahlaştırılmış | SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonssolarwinds · virtualization manager · CWE-264 | Yüksek7,8 | KEV | %3,7 | 17 Haz 2016 |
60Bu hafta | CVE-2015-7766Silahlaştırılmış | PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vizohocorp · manageengine opmanager · CWE-264 | Kritik9,0 | — | %80,6 | 9 Eki 2015 |
60Bu hafta | CVE-2009-3068Silahlaştırılmış | Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers toadobe · robohelp server · CWE-264 | Kritik9,3 | — | %78,2 | 4 Eyl 2009 |
60Bu hafta | CVE-2016-1909Silahlaştırılmış | Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.fortinet · fortios · CWE-264 | Kritik9,8 | — | %71,3 | 15 Oca 2016 |
60Bu hafta | CVE-2011-5010Silahlaştırılmış | apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters ictekproducts · skyrouter · CWE-264 | Kritik10,0 | — | %65,7 | 24 Ara 2011 |
59Planlayın | CVE-2014-0112Silahlaştırılmış | ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackersapache · struts · CWE-264 | Yüksek7,5 | — | %97,9 | 29 Nis 2014 |
59Planlayın | CVE-2010-1240Silahlaştırılmış | Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in tadobe · acrobat reader · CWE-264 | Kritik9,3 | — | %73,6 | 5 Nis 2010 |
59Planlayın | CVE-2014-0514Silahlaştırılmış | The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to eadobe · adobe reader · CWE-264 | Kritik9,3 | — | %72,2 | 15 Nis 2014 |
59Planlayın | CVE-2016-6662Kavram kanıtı | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x beforeoracle · mysql · CWE-264 | Kritik9,8 | — | %67,7 | 20 Eyl 2016 |
59Planlayın | CVE-2012-0299Silahlaştırılmış | The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary codesymantec · web gateway · CWE-264 | Kritik10,0 | — | %63,7 | 21 May 2012 |
58Planlayın | CVE-2017-6622Kavram kanıtı | A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass aucisco · prime collaboration provisioning · CWE-264 | Kritik9,8 | — | %62,2 | 18 May 2017 |
58Planlayın | CVE-2014-2321Kavram kanıtı | web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstzte · f460 · CWE-264 | Kritik10,0 | — | %59,3 | 11 Mar 2014 |
57Planlayın | CVE-2015-3628Silahlaştırılmış | The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,f5 · big-iq security · CWE-264 | Kritik9,0 | — | %69,3 | 7 Ara 2015 |
- CVE-2013-695565Bu hafta
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 al
KritikCVSS 10,0SilahlaştırılmışEPSS %85synology · diskstation manager9 Oca 2014
- CVE-2019-162064Bu hafta
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %84cisco · data center network manager26 Haz 2019
- CVE-2016-1037264Bu hafta
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port
KritikCVSS 9,8SilahlaştırılmışEPSS %82eir · d1000 modem firmware16 May 2017
- CVE-2014-958364Bu hafta
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and ot
KritikCVSS 10,0SilahlaştırılmışEPSS %80asus · wrt firmware8 Oca 2015
- CVE-2009-384364Bu hafta
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers
KritikCVSS 10,0SilahlaştırılmışEPSS %79hp · operations manager23 Kas 2009
- CVE-2015-770964Bu hafta
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication
KritikCVSS 10,0SilahlaştırılmışEPSS %79arkeia · western digital arkeia5 Eki 2015
- CVE-2014-786263Bu hafta
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create ad
KritikCVSS 9,8SilahlaştırılmışEPSS %81zohocorp · desktop central4 Oca 2018
- CVE-1999-101163Bu hafta
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, wh
KritikCVSS 10,0SilahlaştırılmışEPSS %77microsoft · data access components19 Tem 1999
- CVE-2015-279462Bu hafta
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via
KritikCVSS 9,8Kavram kanıtıEPSS %75dnnsoftware · dotnetnuke6 Şub 2017
- CVE-2015-228462Bu hafta
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbi
KritikCVSS 10,0SilahlaştırılmışEPSS %73solarwinds · firewall security manager24 Mar 2015
- CVE-2007-281562Bu hafta
The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL
KritikCVSS 10,0Kavram kanıtıEPSS %73microsoft · internet information services22 May 2007
- CVE-2012-029762Bu hafta
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote
KritikCVSS 10,0SilahlaştırılmışEPSS %73symantec · web gateway21 May 2012
- CVE-2016-364362Bu hafta
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demons
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %4solarwinds · virtualization manager17 Haz 2016
- CVE-2015-776660Bu hafta
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions vi
KritikCVSS 9,0SilahlaştırılmışEPSS %81zohocorp · manageengine opmanager9 Eki 2015
- CVE-2009-306860Bu hafta
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to
KritikCVSS 9,3SilahlaştırılmışEPSS %78adobe · robohelp server4 Eyl 2009
- CVE-2016-190960Bu hafta
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.
KritikCVSS 9,8SilahlaştırılmışEPSS %71fortinet · fortios15 Oca 2016
- CVE-2011-501060Bu hafta
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters i
KritikCVSS 10,0SilahlaştırılmışEPSS %66ctekproducts · skyrouter24 Ara 2011
- CVE-2014-011259Planlayın
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers
YüksekCVSS 7,5SilahlaştırılmışEPSS %98apache · struts29 Nis 2014
- CVE-2010-124059Planlayın
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in t
KritikCVSS 9,3SilahlaştırılmışEPSS %74adobe · acrobat reader5 Nis 2010
- CVE-2014-051459Planlayın
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to e
KritikCVSS 9,3SilahlaştırılmışEPSS %72adobe · adobe reader15 Nis 2014
- CVE-2016-666259Planlayın
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before
KritikCVSS 9,8Kavram kanıtıEPSS %68oracle · mysql20 Eyl 2016
- CVE-2012-029959Planlayın
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code
KritikCVSS 10,0SilahlaştırılmışEPSS %64symantec · web gateway21 May 2012
- CVE-2017-662258Planlayın
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass au
KritikCVSS 9,8Kavram kanıtıEPSS %62cisco · prime collaboration provisioning18 May 2017
- CVE-2014-232158Planlayın
web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonst
KritikCVSS 10,0Kavram kanıtıEPSS %59zte · f46011 Mar 2014
- CVE-2015-362857Planlayın
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6,
KritikCVSS 9,0SilahlaştırılmışEPSS %69f5 · big-iq security7 Ara 2015