Vulnerability index

Browse CVEs

1,385 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Default PermissionsCWE-276 × clear
CRITICAL 9.8 CVE-2017-0847 An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999. Android Patch available Fix from $2,3002017-11-16 HIGH 8.8 CVE-2017-16522 MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices allow remote authenticated users to obtain root access by specifying… Gpt 2541gnac Firmware No fix yet Fix from $1,9502017-11-03 MEDIUM 6.5 CVE-2017-1000084 Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was run… Parameterized Trigger Mitigation only Fix from $1,6002017-10-05 MEDIUM 5.3 CVE-2017-1000089 Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. … Pipeline\ after 2.5 Fix from $1,6002017-10-05 HIGH 8.8 CVE-2017-12230 A vulnerability in the web-based user interface (web UI) of Cisco IOS XE 16.2 could allow an authenticated, remote attacker to elevate their privileg… Ios Xe Mitigation only Fix from $1,9502017-09-29 HIGH 7.8 CVE-2017-14424 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/passwd perm… Dir 850l Firmware No fix yet Fix from $1,9502017-09-13 HIGH 7.8 CVE-2017-14425 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/etc/hnapass… Dir 850l Firmware No fix yet Fix from $1,9502017-09-13 HIGH 7.8 CVE-2017-14427 D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices have 0666 /var/run/storage… Dir 850l Firmware No fix yet Fix from $1,9502017-09-13 HIGH 7.1 CVE-2017-12699 An Incorrect Default Permissions issue was discovered in AzeoTech DAQFactory versions prior to 17.1. Local, non-administrative users may be able to r… Daqfactory after 16.3 Fix from $1,9502017-09-09 HIGH 8.8 CVE-2017-12763 An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to loc… Nomachine after 5.3.9 Fix from $1,9502017-08-29 HIGH 8.8 CVE-2017-11610EPSS 87% The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to ex… Fedora after 3.0 Fix from $1,9502017-08-23 HIGH 7.8 CVE-2017-11156 Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows re… Download Station Mitigation only Fix from $1,9502017-08-14 HIGH 8.8 CVE-2017-11741 HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local user… Vagrant Vmware Fusion after 4.0.23 Fix from $1,9502017-08-08 HIGH 7.1 CVE-2017-1382 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 might create files using the default permissions instead of the customized permissions when c… Websphere Application Server after 9.0.0.4 Fix from $1,9502017-07-24 HIGH 7.5 CVE-2017-4975 An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security… Pcf Tile Generator after 5.0.7 Fix from $1,9502017-06-13 HIGH 7.8 CVE-2017-7968 An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon inst… Wonderware Indusoft Web Studio after 8.0 Fix from $1,9502017-05-19 CRITICAL 9.8 CVE-2017-5642 During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. Ambari Mitigation only Fix from $2,3002017-04-03 MEDIUM 5.9 CVE-2017-5622 With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a … Oxygenos after 4.0.2 Fix from $1,6002017-03-26 MEDIUM 5.5 CVE-2017-6404 An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction … Netbackup after 7.6.1.2 Fix from $1,6002017-03-02 HIGH 7.8 CVE-2016-5425 The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions f… Tomcat No fix yet Fix from $1,9502016-10-13 HIGH 7.8 CVE-2016-3943 Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Securi… Panda Endpoint Administration Agent after 7.49 Fix from $1,9502016-04-18 HIGH 7.8 CVE-2015-7378 Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local … Panda Url Filtering after 4.3.1.8 Fix from $1,9502016-04-18 HIGH 7.2 CVE-2015-7985 Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan… Steam Client No fix yet Fix from $1,9502015-11-24 MEDIUM 5.9 CVE-2013-4394 The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XK… Debian Linux 194+ Fix from $1,6002013-10-28 MEDIUM 5.5 CVE-2013-0266 A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world… Essex Patch available Fix from $1,6002013-03-08 CRITICAL 9.8 CVE-2013-0632 KEVEPSS 94% administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code … Coldfusion Mitigation only Fix from $2,3002013-01-17 MEDIUM 5.0 CVE-2011-4361 MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive in… Debian Linux 1.17.1+ Fix from $1,6002012-01-08 MEDIUM 6.8 CVE-2011-2859 Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors. Chrome 14.0.835.163+ Fix from $1,6002011-09-19 MEDIUM 5.0 CVE-2011-1435 Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files vi… Chrome 11.0.696.57+ Fix from $1,6002011-05-03 HIGH 8.8 CVE-2006-5014 Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqlad… Cpanel Patch available Fix from $1,9502006-09-27