CWE-358

Improperly Implemented Security Check for Standard

Parent: CWE-573 - Improper Following of Specification by Caller

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

132 vulnerabilities with CWE-358
CVE-2019-3894 HIGH
Wildfly 11.0.0-15.0.0 - Security Identity Confusion via ElytronManagedThread
CVSS 8.8
CVE-2019-3806 HIGH
PowerDNS Recursor >=4.1.3 <4.1.9 - Privilege Escalation
CVSS 8.1
CVE-2018-20934 MEDIUM
cPanel 61.9999.55-70.0.22 - Unauthenticated E-mail Account Suspension Bypass
CVSS 6.5
CVE-2018-16860 HIGH
Samba <4.8.12, <4.9.8, <4.10.3 - Privilege Escalation
CVSS 7.5
CVE-2018-16857 HIGH
Samba 4.9.0-4.9.3 - Improperly Implemented Security Check for Standard
CVSS 7.4
CVE-2018-7685 HIGH
libzypp < 17.5.0 - Improperly Implemented Security Check for Corrupted RPM Cache
CVSS 7.8
CVE-2018-1243 HIGH
Dell EMC iDRAC6 <2.91 - iDRAC7/iDRAC8 <2.60.60.60 - iDRAC9 <3.21.21...
CVSS 7.5
CVE-2018-0268 CRITICAL
Cisco DNA Center - Privilege Escalation
CVSS 10.0
CVE-2018-1275 CRITICAL
Spring Framework 4.3.0-4.3.15 - Remote Code Execution via STOMP over WebSocket
CVSS 9.8
CVE-2018-1270 CRITICAL
Spring Framework < 4.3.16 and 5.0 < 5.0.5 - Remote Code Execution via STOMP over WebSocket
CVSS 9.8
CVE-2017-2604 MEDIUM
Jenkins <2.44 - Privilege Escalation
CVSS 4.3
CVE-2017-2612 MEDIUM
Jenkins <2.44, 2.32.2 - Privilege Escalation
CVSS 5.4
CVE-2017-2611 MEDIUM
Jenkins <2.44, 2.32.2 - Privilege Escalation
CVSS 4.3
CVE-2017-15706 MEDIUM
Apache Tomcat 7.0.79-9.0.1 - Info Disclosure
CVSS 5.3
CVE-2017-15107 HIGH
dnsmasq <= 2.78 - DNSSEC Validation Bypass via Wildcard NSEC Record
CVSS 7.5
CVE-2017-15105 MEDIUM
Unbound < 1.6.8 - Improperly Implemented Security Check for Standard
CVSS 5.3
CVE-2017-15091 HIGH
PowerDNS Authoritative 3.0-3.4.11 and 4.0-4.0.4 - Authenticated Unauthorized State Change via API
CVSS 7.1
CVE-2017-15665 HIGH
Flexense DiskBoss Enterprise 8.5.12 - Denial of Service via Crafted SERVER_GET_INFO Packet
CVSS 7.5
CVE-2017-15664 HIGH
Flexense Syncbreeze - Denial of Service
CVSS 7.5
CVE-2017-15663 HIGH
Flexense Disk Pulse Enterprise 10.1.18 - Denial of Service via Crafted SERVER_GET_INFO Packet
CVSS 7.5
CVE-2017-15662 HIGH
Flexense VX Search Enterprise 10.1.12 - Denial of Service via Crafted SERVER_GET_INFO Packet
CVSS 7.5
CVE-2017-8152 MEDIUM
Huawei Honor 5S <TAG-TL00C01B173 - Privilege Escalation
CVSS 4.6
CVE-2017-12303 MEDIUM
Cisco AsyncOS Software - Auth Bypass
CVSS 5.3
CVE-2017-6032 MEDIUM
Schneider Electric Modicon - Info Disclosure
CVSS 5.3
CVE-2017-7177 HIGH
Suricata < 3.2 - IPv4 Fragment Evasion via Missing Protocol Check
CVSS 7.5
Details
Vulnerabilities 132