Vulnerabilities (CVE)

Filtered by CWE-254
Total 416 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4781 1 Apple 1 Iphone Os 2017-07-27 4.6 MEDIUM 6.8 MEDIUM
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypass the passcode attempt counter and unlock a device via unspecified vectors.
CVE-2016-4689 1 Apple 1 Iphone Os 2017-07-27 5.0 MEDIUM 7.5 HIGH
An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature that used a revoked certificate.
CVE-2015-3170 1 Selinux Project 1 Selinux 2017-07-26 2.1 LOW 5.5 MEDIUM
selinux-policy when sysctl fs.protected_hardlinks are set to 0 allows local users to cause a denial of service (SSH login prevention) by creating a hardlink to /etc/passwd from a directory named .config, and updating selinux-policy.
CVE-2016-10336 1 Google 1 Android 2017-07-08 4.3 MEDIUM 5.5 MEDIUM
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
CVE-2016-10332 1 Google 1 Android 2017-07-08 4.3 MEDIUM 5.5 MEDIUM
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
CVE-2016-3997 1 Netapp 1 Clustered Data Ontap 2017-07-05 6.8 MEDIUM 7.5 HIGH
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
CVE-2016-9861 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 5.0 MEDIUM 7.5 HIGH
An issue was discovered in phpMyAdmin. Due to the limitation in URL matching, it was possible to bypass the URL white-list protection. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CVE-2016-9851 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to bypass the logout timeout. All 4.6.x versions (prior to 4.6.5), and 4.4.x versions (prior to 4.4.15.9) are affected.
CVE-2016-9850 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 5.0 MEDIUM 5.3 MEDIUM
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
CVE-2016-6629 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 10.0 HIGH 9.8 CRITICAL
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-6628 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 6.8 MEDIUM 6.3 MEDIUM
An issue was discovered in phpMyAdmin. An attacker may be able to trigger a user to download a specially crafted malicious SVG file. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-6626 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 5.8 MEDIUM 5.4 MEDIUM
An issue was discovered in phpMyAdmin. An attacker could redirect a user to a malicious web page. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-6624 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 4.3 MEDIUM 5.9 MEDIUM
An issue was discovered in phpMyAdmin involving improper enforcement of the IP-based authentication rules. When phpMyAdmin is used with IPv6 in a proxy server environment, and the proxy server is in the allowed range but the attacking computer is not allowed, this vulnerability can allow the attacking computer to connect despite the IP rules. All 4.6.x versions (prior to 4.6.4), 4.4.x versions (prior to 4.4.15.8), and 4.0.x versions (prior to 4.0.10.17) are affected.
CVE-2016-5702 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 4.3 MEDIUM 3.7 LOW
phpMyAdmin 4.6.x before 4.6.3, when the environment lacks a PHP_SELF value, allows remote attackers to conduct cookie-attribute injection attacks via a crafted URI.
CVE-2016-4412 1 Phpmyadmin 1 Phpmyadmin 2017-07-01 3.6 LOW 4.4 MEDIUM
An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attacker must sniff the user's valid phpMyAdmin token. All 4.0.x versions (prior to 4.0.10.16) are affected.
CVE-2014-8583 1 Modwsgi 1 Mod Wsgi 2017-07-01 6.9 MEDIUM N/A
mod_wsgi before 4.2.4 for Apache, when creating a daemon process group, does not properly handle when group privileges cannot be dropped, which might allow attackers to gain privileges via unspecified vectors.
CVE-2016-9738 1 Ibm 1 Qradar Security Information And Event Manager 2017-06-30 5.0 MEDIUM 7.5 HIGH
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.
CVE-2016-6594 1 Bluecoat 3 Advanced Secure Gateway, Cacheflow, Proxysg 2017-06-24 5.0 MEDIUM 7.5 HIGH
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
CVE-2016-4890 1 Zohocorp 1 Servicedesk Plus 2017-05-13 5.0 MEDIUM 5.3 MEDIUM
ZOHO ManageEngine ServiceDesk Plus before 9.2 uses an insecure method for generating cookies, which makes it easier for attackers to obtain sensitive password information by leveraging access to a cookie.
CVE-2010-1776 1 Apple 1 Iphone Os 2017-05-09 4.9 MEDIUM 4.8 MEDIUM
Find My iPhone on iOS 2.0 through 3.1.3 for iPhone 3G and later and iOS 2.1 through 3.1.3 for iPod touch (2nd generation) and later, when Find My iPhone is disabled, allows remote authenticated users with an associated MobileMe account to wipe the device.