IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous a
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asy
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1)
Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asy
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers t
MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete
The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlie
A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow
IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remo
An error was found in the X-Pack Security 5.3.0 to 5.5.2 privilege enforcement. If a user has either 'delete' or 'index'
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r
MediaWiki before 1.18.5, and 1.19.x before 1.19.2 does not send a restrictive X-Frame-Options HTTP header, which allows
Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authent
An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and b
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that w
Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows a
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent:
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services
Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.
In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM
Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 bef
An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously
The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-
Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot prot
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0r
A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF
A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driv
A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver.
A denial of service vulnerability in Telephony could enable a local malicious application to use a specially crafted fil
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare dire
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restriction
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool tha
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software inte
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linu
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they shoul
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter se
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
Frequently Asked Questions
What is CWE-284?
CWE-284 (CWE-284) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-284?
There are 7,306 CVE records associated with CWE-284 in our database. Of these, 877 are critical severity, 2593 are high severity, and 2830 are medium severity.
How can I protect against CWE-284 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-284 using AI-powered security agents.
Detect CWE-284 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-284 vulnerabilities across your infrastructure.
Get Started