An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious applicati
An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious applicati
Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running W
IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit thi
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path
The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of s
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endp
Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not ch
Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can m
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application
In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vuln
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be use
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem
The daily mandb cleanup job in Man-db before 2.7.6.1-1 as packaged in Ubuntu and Debian allows local users with access t
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user
MyBB (aka MyBulletinBoard) before 1.8.8 on Windows and MyBB Merge System before 1.8.8 on Windows allow remote attackers
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a
IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugin
ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git
An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web app
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal
Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broad
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a
A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 a
go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
Huawei USG5500 with software V300R001C00 and V300R001C00 allows attackers to bypass the anti-DDoS module of the USGs to
The default configuration for Cougar-LG stores sensitive information under the web root with insufficient access control
lg.pl in Cistron-LG 1.01 stores sensitive information under the web root with insufficient access controls, which allows
The SPDY/2 codec in Facebook Proxygen before 2015-11-09 allows remote attackers to conduct hijacking attacks and bypass
Facebook Proxygen before 2015-11-09 mismanages HTTPMessage.request state, which allows remote attackers to conduct hijac
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass i
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging
IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without a
In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack b
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as w
I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dez
FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allow
Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp director
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started