Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Openzfs HIGH 7.8
CVE-2020-24717

OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by mode 0770 being equivalent to…

Fix: after 0.8.4
Fix from $1,950 2020-08-27
Connected Mobile Experiences MEDIUM 6.7
CVE-2020-3152

A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute a…

Mitigation only
Fix from $1,600 2020-08-26
Vision Dynamic Signage Director MEDIUM 5.3
CVE-2020-3484

A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to vie…

Mitigation only
Fix from $1,600 2020-08-26
Vision Dynamic Signage Director MEDIUM 6.3
CVE-2020-3485

A vulnerability in the role-based access control (RBAC) functionality of the web management software of Cisco Vision Dynamic Signage Director could a…

Mitigation only
Fix from $1,600 2020-08-26
Ipecs MEDIUM 6.5
CVE-2020-7824

A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vul…

Fix: after 2.10.14
Fix from $1,600 2020-08-25
Windows 10 HIGH 7.3
CVE-2020-1571

An elevation of privilege vulnerability exists in Windows Setup in the way it handles permissions. A locally authenticated attacker could run arbitra…

Patch available
Fix from $1,950 2020-08-17
Composer Setup HIGH 8.2
CVE-2020-15145

In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit t…

Fix: 6.0.0+
Fix from $1,950 2020-08-14
Mailbox Interface Driver HIGH 7.8
CVE-2020-8743

Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable …

Mitigation only
Fix from $1,950 2020-08-13
Realsense D415 Firmware HIGH 7.8
CVE-2020-8763

Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potent…

Fix: 6.1.160.14+
Fix from $1,950 2020-08-13
Distribution Of Openvino Toolkit HIGH 7.8
CVE-2020-12287

Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enabl…

Fix: 2020.2+
Fix from $1,950 2020-08-13
Youtrack MEDIUM 6.5
CVE-2020-15821

In JetBrains YouTrack before 2020.2.6881, a user without permission is able to create an article draft.

Fix: 2020.2.6881+
Fix from $1,600 2020-08-08
Backports Sle HIGH 7.8
CVE-2020-8026

A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local att…

Fix: after 2.6.2-4.2
Fix from $1,950 2020-08-07
Connect Secure HIGH 7.2
CVE-2020-8219

An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full adminis…

Fix: after 9.0
Fix from $1,950 2020-07-30
Package Analytics HIGH 7.5
CVE-2020-2077

SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized att…

Fix: after 04.0.0
Fix from $1,950 2020-07-29
Pi Api HIGH 7.8
CVE-2020-10606

In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This expl…

Fix: after 4.8.0.18
Fix from $1,950 2020-07-24
Linux Kernel HIGH 7.8
CVE-2020-15852

An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attacker may be granted the I/O po…

Fix: after 5.7.9
Fix from $1,950 2020-07-20
Android MEDIUM 6.7
CVE-2020-0122

In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions…

Patch available
Fix from $1,600 2020-07-17
Silverstripe MEDIUM 5.3
CVE-2020-6165

SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set. This affects silverstripe/recipe-cms.…

Fix: 3.2.4 / 3.3.0+
Fix from $1,600 2020-07-15
Cmciii Pu 9333e0fb Firmware HIGH 8.8
CVE-2020-11955

An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.

Fix: after 6.17.00
Fix from $1,950 2020-07-14
Firefox MEDIUM 6.5
CVE-2020-12415

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirector…

Fix: 78.0+
Fix from $1,600 2020-07-09
Firefox MEDIUM 6.5
CVE-2020-12424

When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of…

Fix: 78.0+
Fix from $1,600 2020-07-09
Jetpack Software Development Kit HIGH 7.8
CVE-2020-5974

NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain dir…

Mitigation only
Fix from $1,950 2020-07-08
Android MEDIUM 5.5
CVE-2020-15578

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID …

Mitigation only
Fix from $1,600 2020-07-07
Big Ip Access Policy Manager HIGH 8.1
CVE-2020-5906

In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blackl…

Fix: after 13.1.3
Fix from $1,950 2020-07-01
Tomcat HIGH 7.8
CVE-2020-8022

A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE …

Fix: 8.0.53-29.32.1 / 9.0.35-3.39.1+
Fix from $1,950 2020-06-29
Hylafax\+ MEDIUM 5.3
CVE-2020-8024

A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local a…

Fix: 5.6.1-lp151.3.7 / 7.0.2-lp152.2.1+
Fix from $1,600 2020-06-29
Idrive HIGH 7.8
CVE-2020-15351

IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify perm…

Fix: 6.7.3.19+
Fix from $1,950 2020-06-26
Mir100 Firmware CRITICAL 9.8
CVE-2020-10279

MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system pre…

Fix: after 2.8.1.1
Fix from $2,300 2020-06-24
Guest Oslogin HIGH 7.8
CVE-2020-8903

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22
Guest Oslogin HIGH 7.8
CVE-2020-8907

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22