Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2020-0562 Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege … Raid Web Console 2 Patch available Fix from $1,9502020-02-13 HIGH 7.8 CVE-2020-0560 Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potent… Renesas Electronics Usb 3.0 Driver Mitigation only Fix from $1,9502020-02-13 HIGH 7.3 CVE-2019-2200 In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a… Android Patch available Fix from $1,9502020-02-13 HIGH 7.8 CVE-2019-14002 APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon C… Apq8053 Firmware Mitigation only Fix from $1,9502020-02-07 HIGH 7.5 CVE-2020-7972 GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). GitLab 12.5.9 / 12.6.6+ Fix from $1,9502020-02-05 MEDIUM 5.3 CVE-2020-7977 GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. GitLab 12.5.9 / 12.6.6+ Fix from $1,6002020-02-05 MEDIUM 5.3 CVE-2020-7979 GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab 12.5.9 / 12.6.6+ Fix from $1,6002020-02-05 CRITICAL 9.8 CVE-2020-8114 GitLab EE 8.9 and later through 12.7.2 has Insecure Permission GitLab 12.5.9 / 12.6.6+ Fix from $2,3002020-02-05 MEDIUM 6.5 CVE-2020-5231 In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE… Opencast 7.6+ Fix from $1,6002020-01-30 HIGH 7.8 CVE-2014-7303 SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly oth… Sgi Tempo No fix yet Fix from $1,9502020-01-27 MEDIUM 6.6 CVE-2014-7301 SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly oth… Sgi Tempo No fix yet Fix from $1,6002020-01-27 HIGH 7.8 CVE-2014-7302 SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary fil… Sgi Tempo No fix yet Fix from $1,9502020-01-27 MEDIUM 5.5 CVE-2019-17103 An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read… Antivirus 8.0.0+ Fix from $1,6002020-01-27 CRITICAL 9.9 CVE-2019-19896 In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IX… Easyinstall No fix yet Fix from $2,3002020-01-23 CRITICAL 9.8 CVE-2019-19392 The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administ… Usersexportimport 1.2.0+ Fix from $2,3002020-01-21 HIGH 7.8 CVE-2019-14601 Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enab… Raid Web Console 3 7.010.009.000+ Fix from $1,9502020-01-17 HIGH 8.1 CVE-2020-5196 Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, l… Ftp Server 10.0.18 / 11.0.3+ Fix from $1,9502020-01-14 HIGH 8.8 CVE-2019-19475 An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is … Manageengine Applications Manager Mitigation only Fix from $1,9502020-01-10 HIGH 8.8 CVE-2012-4434 fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code. Fwknop 2.0.3+ Fix from $1,9502020-01-09 MEDIUM 5.4 CVE-2020-6166 A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings … Minimal Coming Soon \& Maintenance Mode after 2.15 Fix from $1,6002020-01-09 MEDIUM 6.5 CVE-2019-11765 A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However,… Firefox 70.0+ Fix from $1,6002020-01-08 MEDIUM 5.5 CVE-2020-0009 In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalati… Debian Linux Patch available Fix from $1,6002020-01-08 MEDIUM 6.6 CVE-2019-16716 OX App Suite through 7.10.2 has Incorrect Access Control. Open Xchange Appsuite after 7.10.2 Fix from $1,6002020-01-06 HIGH 8.1 CVE-2013-4859EPSS 7% INSTEON Hub 2242-222 lacks Web and API authentication Hub Firmware No fix yet Fix from $1,9502019-12-27 HIGH 7.8 CVE-2019-11097 Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.7… Trusted Execution Engine Firmware 3.1.70 / 4.0.20+ Fix from $1,9502019-12-18 HIGH 7.5 CVE-2019-19724 Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to a… Singularity after 3.5.1 Fix from $1,9502019-12-18 MEDIUM 5.5 CVE-2019-8731 A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This i… Iphone Os 13.0+ Fix from $1,6002019-12-18 HIGH 8.0 CVE-2019-17334 The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire D… Spotfire Analyst after 7.11.1 Fix from $1,9502019-12-17 HIGH 7.8 CVE-2019-19675 In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging… Workspace Control 10.3.180.0+ Fix from $1,9502019-12-17 MEDIUM 5.4 CVE-2019-16559 A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection… Websphere Deployer after 1.6.1 Fix from $1,6002019-12-17