Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
Android CRITICAL 9.8
CVE-2017-0847

An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.

Patch available
Fix from $2,300 2017-11-16
Gpt 2541gnac Firmware HIGH 8.8
CVE-2017-16522

MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying…

No fix yet
Fix from $1,950 2017-11-03
Parameterized Trigger MEDIUM 6.5
CVE-2017-1000084

Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run…

Mitigation only
Fix from $1,600 2017-10-05
Pipeline\ MEDIUM 5.3
CVE-2017-1000089

Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. …

Fix: after 2.5
Fix from $1,600 2017-10-05
Ios Xe HIGH 8.8
CVE-2017-12230

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileg…

Mitigation only
Fix from $1,950 2017-09-29
Dir 850l Firmware HIGH 7.8
CVE-2017-14424

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/passwd perm…

No fix yet
Fix from $1,950 2017-09-13
Dir 850l Firmware HIGH 7.8
CVE-2017-14425

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapass…

No fix yet
Fix from $1,950 2017-09-13
Dir 850l Firmware HIGH 7.8
CVE-2017-14427

D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage…

No fix yet
Fix from $1,950 2017-09-13
Daqfactory HIGH 7.1
CVE-2017-12699

An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to r…

Fix: after 16.3
Fix from $1,950 2017-09-09
Nomachine HIGH 8.8
CVE-2017-12763

An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loc…

Fix: after 5.3.9
Fix from $1,950 2017-08-29
Fedora HIGH 8.8
CVE-2017-11610EPSS 87%

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to ex…

Fix: after 3.0
Fix from $1,950 2017-08-23
Download Station HIGH 7.8
CVE-2017-11156

Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows re…

Mitigation only
Fix from $1,950 2017-08-14
Vagrant Vmware Fusion HIGH 8.8
CVE-2017-11741

HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local user…

Fix: after 4.0.23
Fix from $1,950 2017-08-08
Websphere Application Server HIGH 7.1
CVE-2017-1382

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when c…

Fix: after 9.0.0.4
Fix from $1,950 2017-07-24
Pcf Tile Generator HIGH 7.5
CVE-2017-4975

An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security…

Fix: after 5.0.7
Fix from $1,950 2017-06-13
Wonderware Indusoft Web Studio HIGH 7.8
CVE-2017-7968

An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon inst…

Fix: after 8.0
Fix from $1,950 2017-05-19
Ambari CRITICAL 9.8
CVE-2017-5642

During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

Mitigation only
Fix from $2,300 2017-04-03
Oxygenos MEDIUM 5.9
CVE-2017-5622

With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a …

Fix: after 4.0.2
Fix from $1,600 2017-03-26
Netbackup MEDIUM 5.5
CVE-2017-6404

An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction …

Fix: after 7.6.1.2
Fix from $1,600 2017-03-02
Tomcat HIGH 7.8
CVE-2016-5425

The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions f…

No fix yet
Fix from $1,950 2016-10-13
Panda Endpoint Administration Agent HIGH 7.8
CVE-2016-3943

Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Securi…

Fix: after 7.49
Fix from $1,950 2016-04-18
Panda Url Filtering HIGH 7.8
CVE-2015-7378

Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local …

Fix: after 4.3.1.8
Fix from $1,950 2016-04-18
Steam Client HIGH 7.2
CVE-2015-7985

Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan…

No fix yet
Fix from $1,950 2015-11-24
Debian Linux MEDIUM 5.9
CVE-2013-4394

The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XK…

Fix: 194+
Fix from $1,600 2013-10-28
Essex MEDIUM 5.5
CVE-2013-0266

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world…

Patch available
Fix from $1,600 2013-03-08
Coldfusion CRITICAL 9.8
CVE-2013-0632 KEVEPSS 94%

administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code …

Mitigation only
Fix from $2,300 2013-01-17
Debian Linux MEDIUM 5.0
CVE-2011-4361

MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive in…

Fix: 1.17.1+
Fix from $1,600 2012-01-08
Chrome MEDIUM 6.8
CVE-2011-2859

Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.

Fix: 14.0.835.163+
Fix from $1,600 2011-09-19
Chrome MEDIUM 5.0
CVE-2011-1435

Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files vi…

Fix: 11.0.696.57+
Fix from $1,600 2011-05-03
Cpanel HIGH 8.8
CVE-2006-5014

Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqlad…

Patch available
Fix from $1,950 2006-09-27