Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Gvfs HIGH 7.8
CVE-2019-12795

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket witho…

Fix: 1.38.3 / 1.40.2+
Fix from $1,950 2019-06-11
Debian Linux CRITICAL 9.8
CVE-2019-12450

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre…

Fix: after 2.61.1
Fix from $2,300 2019-05-29
Somachine Basic MEDIUM 5.5
CVE-2018-7822

An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior…

Fix: 1.10.0.0+
Fix from $1,600 2019-05-22
Fedora MEDIUM 6.1
CVE-2019-3870

A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files …

Fix: 2.3.6-1720 / 4.9.6+
Fix from $1,600 2019-04-09
Diskstation Manager MEDIUM 6.5
CVE-2018-13286

Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated use…

Fix: 5.2-5967-8 / 6.0.3-8754-8+
Fix from $1,600 2019-04-01
Router Manager MEDIUM 6.5
CVE-2018-13287

Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users t…

Fix: 1.1.7-6941-1+
Fix from $1,600 2019-04-01
Android HIGH 7.8
CVE-2018-11906

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a security concern with default p…

Patch available
Fix from $1,950 2018-11-27
Corsair Utility Engine HIGH 7.8
CVE-2018-12441

The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute…

Mitigation only
Fix from $1,950 2018-10-11
Telem Gw6 Firmware HIGH 8.8
CVE-2018-10605

Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full co…

Fix: 2.0.87-4018403-k4+
Fix from $1,950 2018-10-01
Enterprise Linux Desktop MEDIUM 5.0
CVE-2018-14650

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada…

Patch available
Fix from $1,600 2018-09-27
E Alert Firmware HIGH 7.5
CVE-2018-8848

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exp…

Mitigation only
Fix from $1,950 2018-09-26
Distribution For Python HIGH 7.8
CVE-2018-12175

Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via l…

Mitigation only
Fix from $1,950 2018-09-12
Data Migration Software MEDIUM 5.3
CVE-2018-12160

DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to …

Fix: after 3.1
Fix from $1,600 2018-09-12
Simatic Step 7 \(tia Portal\) HIGH 7.8
CVE-2018-11453

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a…

Mitigation only
Fix from $1,950 2018-08-07
Simatic Step 7 \(tia Portal\) HIGH 8.6
CVE-2018-11454

A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a…

No fix yet
Fix from $1,950 2018-08-07
U818a Firmware HIGH 8.1
CVE-2017-3209

The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. …

Mitigation only
Fix from $1,950 2018-07-24
Portrait Display Sdk HIGH 7.8
CVE-2017-3210

Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code exec…

Fix: 2.34+
Fix from $1,950 2018-07-24
Sel Compass HIGH 8.8
CVE-2018-10604

SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files…

Fix: after 3.0.5.1
Fix from $1,950 2018-07-24
H2 MEDIUM 6.5
CVE-2018-14335EPSS 13%

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of t…

No fix yet
Fix from $1,600 2018-07-24
Data Loss Prevention Endpoint HIGH 7.4
CVE-2018-6683

Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.…

Fix: 10.0.505 / 11.0.405+
Fix from $1,950 2018-07-23
Totalav HIGH 7.8
CVE-2018-7535

An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Eve…

Fix: after 4.6.19
Fix from $1,950 2018-07-13
Firefox HIGH 7.8
CVE-2017-7794

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only …

Fix: 55.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.5
CVE-2017-7761

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with c…

Fix: 52.2.0 / 54.0+
Fix from $1,600 2018-06-11
Pandora Doomsday CRITICAL 9.8
CVE-2017-16127

The module pandora-doomsday infects other modules. It's since been unpublished from the registry.

No fix yet
Fix from $2,300 2018-06-07
Npm Script Demo CRITICAL 9.8
CVE-2017-16128

The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.

Mitigation only
Fix from $2,300 2018-06-07
Debian Linux MEDIUM 6.5
CVE-2017-0369

Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.

Fix: 1.27.2 / 1.28.1+
Fix from $1,600 2018-04-13
Jsnapy MEDIUM 5.5
CVE-2018-0023

JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and …

Fix: 1.3.0+
Fix from $1,600 2018-04-11
Pi Data Archive HIGH 7.8
CVE-2018-7533

An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow es…

Fix: after 2017
Fix from $1,950 2018-03-14
Enterprise Linux HIGH 7.8
CVE-2017-15131

It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting…

Fix: 0.15.5+
Fix from $1,950 2018-01-09
Unifi Video HIGH 7.8
CVE-2016-6914

Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privilege…

Fix: 3.8.0+
Fix from $1,950 2017-12-27