Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
MEDIUM 5.4 CVE-2019-16552 A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacke… Gerrit Trigger after 2.30.1 Fix from $1,6002019-12-17 MEDIUM 5.3 CVE-2019-19712 Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been e… Contao after 4.8.5 Fix from $1,6002019-12-17 HIGH 7.8 CVE-2019-14605 Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially e… Setup And Configuration Software Platform Discovery Utility Mitigation only Fix from $1,9502019-12-16 HIGH 7.8 CVE-2019-0134 Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially… Dynamic Platform And Thermal Framework after 8.3.10208.5643 Fix from $1,9502019-12-16 HIGH 7.8 CVE-2019-14568 Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation o… Rapid Storage Technology 17.7.0.1006+ Fix from $1,9502019-12-16 HIGH 7.8 CVE-2019-14603 Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenti… Quartus Prime 19.3+ Fix from $1,9502019-12-16 MEDIUM 5.3 CVE-2019-14861 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe pro… Fedora 4.9.17 / 4.10.11+ Fix from $1,6002019-12-10 MEDIUM 5.5 CVE-2019-19460 An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default.… Proaccess Space after 5.5 Fix from $1,6002019-12-03 MEDIUM 6.5 CVE-2019-19118 Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user … Django 2.1.15 / 2.2.8+ Fix from $1,6002019-12-02 HIGH 7.3 CVE-2019-19490 LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe. Litemanager No fix yet Fix from $1,9502019-12-02 HIGH 8.3 CVE-2018-20090 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and g… Data Science Workbench after 1.4.2 Fix from $1,9502019-11-26 HIGH 7.2 CVE-2018-17860 Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. Cdh after 5.14.0 Fix from $1,9502019-11-26 MEDIUM 6.5 CVE-2019-13662 Insufficient policy enforcement in navigations in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass content security policy via… Chrome 77.0.3865.75+ Fix from $1,6002019-11-25 MEDIUM 6.2 CVE-2012-5578 Python keyring has insecure permissions on new databases allowing world-readable files to be created Keyring after 0.10 Fix from $1,6002019-11-25 HIGH 8.8 CVE-2019-19202 In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding … Vtiger Crm 7.2.0+ Fix from $1,9502019-11-21 HIGH 7.8 CVE-2019-17421 Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local … Manageengine Firewall Analyzer Patch available Fix from $1,9502019-11-21 MEDIUM 5.5 CVE-2012-6136 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. Tuned Mitigation only Fix from $1,6002019-11-20 HIGH 7.8 CVE-2019-14602 Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable… Nuvoton Consumer Infrared after 1.02.1002 Fix from $1,9502019-11-14 HIGH 7.5 CVE-2010-5108 Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and res… Debian Linux Mitigation only Fix from $1,9502019-11-13 HIGH 7.1 CVE-2019-4652 IBM Spectrum Protect Plus 10.1.0 through 10.1.4 uses insecure file permissions on restored files and directories in Windows which could allow a local… Spectrum Protect Plus after 10.1.4 Fix from $1,9502019-11-12 MEDIUM 5.5 CVE-2013-1425 ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions. Debian Linux 1.0.4+ Fix from $1,6002019-11-07 MEDIUM 5.3 CVE-2019-1982 A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Ci… Firepower Services Software For Asa Mitigation only Fix from $1,6002019-11-05 MEDIUM 6.1 CVE-2019-12752 The Symantec SONAR component, prior to 12.0.2, may be susceptible to a tamper protection bypass vulnerability which could potentially allow an attack… Sonar 12.0.2+ Fix from $1,6002019-11-01 MEDIUM 5.3 CVE-2019-18367 In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions. Teamcity 2019.1.2+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18369 In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible. Youtrack 2019.2.55152+ Fix from $1,6002019-10-31 MEDIUM 5.3 CVE-2019-18366 In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission. Teamcity 2019.1.2+ Fix from $1,6002019-10-31 HIGH 7.5 CVE-2012-5577 Python keyring lib before 0.10 created keyring files with world-readable permissions. Keyring 0.10+ Fix from $1,9502019-10-28 MEDIUM 6.5 CVE-2019-14925 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/sma… Smartrtu Firmware after 3.0 Fix from $1,6002019-10-28 MEDIUM 6.5 CVE-2019-10469 A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attac… Kubernetes Ci after 1.3 Fix from $1,6002019-10-23 MEDIUM 6.5 CVE-2019-10470 A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to en… Kubernetes Ci after 1.3 Fix from $1,6002019-10-23