Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Gerrit Trigger MEDIUM 5.4
CVE-2019-16552

A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke…

Fix: after 2.30.1
Fix from $1,600 2019-12-17
Contao MEDIUM 5.3
CVE-2019-19712

Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e…

Fix: after 4.8.5
Fix from $1,600 2019-12-17
Setup And Configuration Software Platform Discovery Utility HIGH 7.8
CVE-2019-14605

Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially e…

Mitigation only
Fix from $1,950 2019-12-16
Dynamic Platform And Thermal Framework HIGH 7.8
CVE-2019-0134

Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially…

Fix: after 8.3.10208.5643
Fix from $1,950 2019-12-16
Rapid Storage Technology HIGH 7.8
CVE-2019-14568

Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation o…

Fix: 17.7.0.1006+
Fix from $1,950 2019-12-16
Quartus Prime HIGH 7.8
CVE-2019-14603

Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenti…

Fix: 19.3+
Fix from $1,950 2019-12-16
Fedora MEDIUM 5.3
CVE-2019-14861

All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe pro…

Fix: 4.9.17 / 4.10.11+
Fix from $1,600 2019-12-10
Proaccess Space MEDIUM 5.5
CVE-2019-19460

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default.…

Fix: after 5.5
Fix from $1,600 2019-12-03
Django MEDIUM 6.5
CVE-2019-19118

Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user …

Fix: 2.1.15 / 2.2.8+
Fix from $1,600 2019-12-02
Litemanager HIGH 7.3
CVE-2019-19490

LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe.

No fix yet
Fix from $1,950 2019-12-02
Data Science Workbench HIGH 8.3
CVE-2018-20090

An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and g…

Fix: after 1.4.2
Fix from $1,950 2019-11-26
Cdh HIGH 7.2
CVE-2018-17860

Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1.

Fix: after 5.14.0
Fix from $1,950 2019-11-26
Chrome MEDIUM 6.5
CVE-2019-13662

Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via…

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Keyring MEDIUM 6.2
CVE-2012-5578

Python keyring has insecure permissions on new databases allowing world-readable files to be created

Fix: after 0.10
Fix from $1,600 2019-11-25
Vtiger Crm HIGH 8.8
CVE-2019-19202

In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding …

Fix: 7.2.0+
Fix from $1,950 2019-11-21
Manageengine Firewall Analyzer HIGH 7.8
CVE-2019-17421

Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local …

Patch available
Fix from $1,950 2019-11-21
Tuned MEDIUM 5.5
CVE-2012-6136

tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

Mitigation only
Fix from $1,600 2019-11-20
Nuvoton Consumer Infrared HIGH 7.8
CVE-2019-14602

Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable…

Fix: after 1.02.1002
Fix from $1,950 2019-11-14
Debian Linux HIGH 7.5
CVE-2010-5108

Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res…

Mitigation only
Fix from $1,950 2019-11-13
Spectrum Protect Plus HIGH 7.1
CVE-2019-4652

IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local…

Fix: after 10.1.4
Fix from $1,950 2019-11-12
Debian Linux MEDIUM 5.5
CVE-2013-1425

ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.

Fix: 1.0.4+
Fix from $1,600 2019-11-07
Firepower Services Software For Asa MEDIUM 5.3
CVE-2019-1982

A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Ci…

Mitigation only
Fix from $1,600 2019-11-05
Sonar MEDIUM 6.1
CVE-2019-12752

The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attack…

Fix: 12.0.2+
Fix from $1,600 2019-11-01
Teamcity MEDIUM 5.3
CVE-2019-18367

In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.

Fix: 2019.1.2+
Fix from $1,600 2019-10-31
Youtrack MEDIUM 5.3
CVE-2019-18369

In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.

Fix: 2019.2.55152+
Fix from $1,600 2019-10-31
Teamcity MEDIUM 5.3
CVE-2019-18366

In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.

Fix: 2019.1.2+
Fix from $1,600 2019-10-31
Keyring HIGH 7.5
CVE-2012-5577

Python keyring lib before 0.10 created keyring files with world-readable permissions.

Fix: 0.10+
Fix from $1,950 2019-10-28
Smartrtu Firmware MEDIUM 6.5
CVE-2019-14925

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/sma…

Fix: after 3.0
Fix from $1,600 2019-10-28
Kubernetes Ci MEDIUM 6.5
CVE-2019-10469

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac…

Fix: after 1.3
Fix from $1,600 2019-10-23
Kubernetes Ci MEDIUM 6.5
CVE-2019-10470

A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en…

Fix: after 1.3
Fix from $1,600 2019-10-23