Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Raid Web Console 2 HIGH 7.8
CVE-2020-0562

Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege …

Patch available
Fix from $1,950 2020-02-13
Renesas Electronics Usb 3.0 Driver HIGH 7.8
CVE-2020-0560

Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potent…

Mitigation only
Fix from $1,950 2020-02-13
Android HIGH 7.3
CVE-2019-2200

In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a…

Patch available
Fix from $1,950 2020-02-13
Apq8053 Firmware HIGH 7.8
CVE-2019-14002

APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon C…

Mitigation only
Fix from $1,950 2020-02-07
GitLab HIGH 7.5
CVE-2020-7972

GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).

Fix: 12.5.9 / 12.6.6+
Fix from $1,950 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7977

GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab MEDIUM 5.3
CVE-2020-7979

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

Fix: 12.5.9 / 12.6.6+
Fix from $1,600 2020-02-05
GitLab CRITICAL 9.8
CVE-2020-8114

GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

Fix: 12.5.9 / 12.6.6+
Fix from $2,300 2020-02-05
Opencast MEDIUM 6.5
CVE-2020-5231

In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE…

Fix: 7.6+
Fix from $1,600 2020-01-30
Sgi Tempo HIGH 7.8
CVE-2014-7303

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly oth…

No fix yet
Fix from $1,950 2020-01-27
Sgi Tempo MEDIUM 6.6
CVE-2014-7301

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly oth…

No fix yet
Fix from $1,600 2020-01-27
Sgi Tempo HIGH 7.8
CVE-2014-7302

SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary fil…

No fix yet
Fix from $1,950 2020-01-27
Antivirus MEDIUM 5.5
CVE-2019-17103

An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read…

Fix: 8.0.0+
Fix from $1,600 2020-01-27
Easyinstall CRITICAL 9.9
CVE-2019-19896

In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IX…

No fix yet
Fix from $2,300 2020-01-23
Usersexportimport CRITICAL 9.8
CVE-2019-19392

The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administ…

Fix: 1.2.0+
Fix from $2,300 2020-01-21
Raid Web Console 3 HIGH 7.8
CVE-2019-14601

Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enab…

Fix: 7.010.009.000+
Fix from $1,950 2020-01-17
Ftp Server HIGH 8.1
CVE-2020-5196

Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, l…

Fix: 10.0.18 / 11.0.3+
Fix from $1,950 2020-01-14
Manageengine Applications Manager HIGH 8.8
CVE-2019-19475

An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is …

Mitigation only
Fix from $1,950 2020-01-10
Fwknop HIGH 8.8
CVE-2012-4434

fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.

Fix: 2.0.3+
Fix from $1,950 2020-01-09
Minimal Coming Soon \& Maintenance Mode MEDIUM 5.4
CVE-2020-6166

A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings …

Fix: after 2.15
Fix from $1,600 2020-01-09
Firefox MEDIUM 6.5
CVE-2019-11765

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However,…

Fix: 70.0+
Fix from $1,600 2020-01-08
Debian Linux MEDIUM 5.5
CVE-2020-0009

In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalati…

Patch available
Fix from $1,600 2020-01-08
Open Xchange Appsuite MEDIUM 6.6
CVE-2019-16716

OX App Suite through 7.10.2 has Incorrect Access Control.

Fix: after 7.10.2
Fix from $1,600 2020-01-06
Hub Firmware HIGH 8.1
CVE-2013-4859EPSS 7%

INSTEON Hub 2242-222 lacks Web and API authentication

No fix yet
Fix from $1,950 2019-12-27
Trusted Execution Engine Firmware HIGH 7.8
CVE-2019-11097

Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.7…

Fix: 3.1.70 / 4.0.20+
Fix from $1,950 2019-12-18
Singularity HIGH 7.5
CVE-2019-19724

Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to a…

Fix: after 3.5.1
Fix from $1,950 2019-12-18
Iphone Os MEDIUM 5.5
CVE-2019-8731

A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This i…

Fix: 13.0+
Fix from $1,600 2019-12-18
Spotfire Analyst HIGH 8.0
CVE-2019-17334

The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire D…

Fix: after 7.11.1
Fix from $1,950 2019-12-17
Workspace Control HIGH 7.8
CVE-2019-19675

In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging…

Fix: 10.3.180.0+
Fix from $1,950 2019-12-17
Websphere Deployer MEDIUM 5.4
CVE-2019-16559

A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection…

Fix: after 1.6.1
Fix from $1,600 2019-12-17