Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Guest Oslogin HIGH 7.8
CVE-2020-8933

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/co…

Fix: after 20200507.00
Fix from $1,950 2020-06-22
Apq8053 Firmware HIGH 7.8
CVE-2020-3626

Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon C…

Mitigation only
Fix from $1,950 2020-06-22
Mattermost Server CRITICAL 9.8
CVE-2017-18915

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. After a restart of a server, an attacker might suddenly gain API Endpoin…

Fix: 3.6.7 / 3.7.5+
Fix from $2,300 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20889

An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.

Fix: 4.10.5 / 5.5.2+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2019-20882

An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.

Fix: 5.8.0+
Fix from $1,600 2020-06-19
Rtslib Fb HIGH 7.8
CVE-2020-14019

Open-iSCSI rtslib-fb through 2.1.72 has weak permissions for /etc/target/saveconfig.json because shutil.copyfile (instead of shutil.copy) is used, an…

Fix: after 2.1.72
Fix from $1,950 2020-06-19
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Omero.server HIGH 7.5
CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model o…

Fix: after 5.6.0
Fix from $1,950 2020-06-17
Openbmc HIGH 8.8
CVE-2020-14156

user_channel/passwd_mgr.cpp in OpenBMC phosphor-host-ipmid before 2020-04-03 does not ensure that /etc/ipmi-pass has strong file permissions.

Fix: 2020-04-03+
Fix from $1,950 2020-06-15
Android HIGH 7.8
CVE-2020-0215

In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local e…

Mitigation only
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0208

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.8
CVE-2020-0209

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additi…

Patch available
Fix from $1,950 2020-06-11
Android HIGH 7.3
CVE-2020-0133

In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to lo…

Patch available
Fix from $1,950 2020-06-11
Mac Os X HIGH 7.8
CVE-2020-9817

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Catalina 10.15.5. A malicious…

Fix: 10.13.6 / 10.14.6+
Fix from $1,950 2020-06-09
Workspace App HIGH 7.8
CVE-2020-13884

Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges d…

Fix: 2006.1+
Fix from $1,950 2020-06-08
Workspace App HIGH 7.8
CVE-2020-13885

Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the app…

Fix: 2006.1+
Fix from $1,950 2020-06-08
Openbrowser MEDIUM 5.4
CVE-2020-8954

OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]

Mitigation only
Fix from $1,600 2020-06-08
Wap131 HIGH 7.5
CVE-2020-12695EPSS 15%

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on…

Fix: 2.0.0+
Fix from $1,950 2020-06-08
Dext5 HIGH 7.5
CVE-2020-13894

handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.

Fix: after 3.5.1402961
Fix from $1,950 2020-06-07
Fedora MEDIUM 5.5
CVE-2020-13867

Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

Fix: after 2.1.52
Fix from $1,600 2020-06-05
Chrome MEDIUM 6.5
CVE-2020-6497

Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c…

Fix: 83.0.4103.88+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6498

Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a c…

Fix: 83.0.4103.88+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6501

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a craft…

Fix: 80.0.3987.87+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6502

Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

Fix: 80.0.3987.87+
Fix from $1,600 2020-06-03
Chrome MEDIUM 6.5
CVE-2020-6495

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.97+
Fix from $1,600 2020-06-03
Xbee 2 Firmware HIGH 7.7
CVE-2017-18868

Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon whi…

Mitigation only
Fix from $1,950 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6487

Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6480

Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation restrictions via U…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6482

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malic…

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21
Chrome MEDIUM 6.5
CVE-2020-6483

Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a …

Fix: 83.0.4103.61+
Fix from $1,600 2020-05-21