Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
HIGH 7.8 CVE-2019-12795 daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket witho… Gvfs 1.38.3 / 1.40.2+ Fix from $1,9502019-06-11 CRITICAL 9.8 CVE-2019-12450 file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progre… Debian Linux after 2.61.1 Fix from $2,3002019-05-29 MEDIUM 5.5 CVE-2018-7822 An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior… Somachine Basic 1.10.0.0+ Fix from $1,6002019-05-22 MEDIUM 6.1 CVE-2019-3870 A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files … Fedora 2.3.6-1720 / 4.9.6+ Fix from $1,6002019-04-09 MEDIUM 6.5 CVE-2018-13286 Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated use… Diskstation Manager 5.2-5967-8 / 6.0.3-8754-8+ Fix from $1,6002019-04-01 MEDIUM 6.5 CVE-2018-13287 Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users t… Router Manager 1.1.7-6941-1+ Fix from $1,6002019-04-01 HIGH 7.8 CVE-2018-11906 In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a security concern with default p… Android Patch available Fix from $1,9502018-11-27 HIGH 7.8 CVE-2018-12441 The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute… Corsair Utility Engine Mitigation only Fix from $1,9502018-10-11 HIGH 8.8 CVE-2018-10605 Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full co… Telem Gw6 Firmware 2.0.87-4018403-k4+ Fix from $1,9502018-10-01 MEDIUM 5.0 CVE-2018-14650 It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada… Enterprise Linux Desktop Patch available Fix from $1,6002018-09-27 HIGH 7.5 CVE-2018-8848 Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exp… E Alert Firmware Mitigation only Fix from $1,9502018-09-26 HIGH 7.8 CVE-2018-12175 Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via l… Distribution For Python Mitigation only Fix from $1,9502018-09-12 MEDIUM 5.3 CVE-2018-12160 DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to … Data Migration Software after 3.1 Fix from $1,6002018-09-12 HIGH 7.8 CVE-2018-11453 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a… Simatic Step 7 \(tia Portal\) Mitigation only Fix from $1,9502018-08-07 HIGH 8.6 CVE-2018-11454 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) a… Simatic Step 7 \(tia Portal\) No fix yet Fix from $1,9502018-08-07 HIGH 8.1 CVE-2017-3209 The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. … U818a Firmware Mitigation only Fix from $1,9502018-07-24 HIGH 7.8 CVE-2017-3210 Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code exec… Portrait Display Sdk 2.34+ Fix from $1,9502018-07-24 HIGH 8.8 CVE-2018-10604 SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files… Sel Compass after 3.0.5.1 Fix from $1,9502018-07-24 MEDIUM 6.5 CVE-2018-14335EPSS 13% An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of t… H2 No fix yet Fix from $1,6002018-07-24 HIGH 7.4 CVE-2018-6683 Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.… Data Loss Prevention Endpoint 10.0.505 / 11.0.405+ Fix from $1,9502018-07-23 HIGH 7.8 CVE-2018-7535 An issue was discovered in TotalAV v4.1.7. An unprivileged user could modify or overwrite all of the product's files because of weak permissions (Eve… Totalav after 4.6.19 Fix from $1,9502018-07-13 HIGH 7.8 CVE-2017-7794 On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only … Firefox 55.0+ Fix from $1,9502018-06-11 MEDIUM 5.5 CVE-2017-7761 The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with c… Firefox 52.2.0 / 54.0+ Fix from $1,6002018-06-11 CRITICAL 9.8 CVE-2017-16127 The module pandora-doomsday infects other modules. It's since been unpublished from the registry. Pandora Doomsday No fix yet Fix from $2,3002018-06-07 CRITICAL 9.8 CVE-2017-16128 The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry. Npm Script Demo Mitigation only Fix from $2,3002018-06-07 MEDIUM 6.5 CVE-2017-0369 Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it. Debian Linux 1.27.2 / 1.28.1+ Fix from $1,6002018-04-13 MEDIUM 5.5 CVE-2018-0023 JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and … Jsnapy 1.3.0+ Fix from $1,6002018-04-11 HIGH 7.8 CVE-2018-7533 An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow es… Pi Data Archive after 2017 Fix from $1,9502018-03-14 HIGH 7.8 CVE-2017-15131 It was found that system umask policy is not being honored when creating XDG user directories, since Xsession sources xdg-user-dirs.sh before setting… Enterprise Linux 0.15.5+ Fix from $1,9502018-01-09 HIGH 7.8 CVE-2016-6914 Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privilege… Unifi Video 3.8.0+ Fix from $1,9502017-12-27