389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entrie
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 allows remote attackers to bypass GlobalBlocking extension IP address
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an exis
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allow
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attack
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users
The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level admi
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators t
Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to by
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT
The make_temporary_filename function in perltidy 20120701-1 and earlier allows local users to obtain sensitive informati
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to exec
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to exec
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to exec
An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to exec
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application t
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application t
An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arb
sudo_noexec.so in Sudo before 1.8.15 on Linux might allow local users to bypass intended noexec command restrictions via
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUB
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUB
ovirt-engine-webadmin, as used in Red Hat Enterprise Virtualization Manager (aka RHEV-M) for Servers and RHEV-M 4.0, all
An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT
The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incor
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
The Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote atta
IBM BigFix Platform could allow an attacker on the local network to crash the BES and relay servers.
IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to ot
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started