Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Galaxy HIGH 7.8
CVE-2020-11827

In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious …

Fix: 1.2.67+
Fix from $1,950 2020-07-14
Disclosure Management MEDIUM 5.4
CVE-2020-6267

Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag.

Mitigation only
Fix from $1,600 2020-07-14
Emc Isilon Onefs HIGH 8.8
CVE-2020-5371

Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with ne…

Fix: after 8.2.2
Fix from $1,950 2020-07-06
Galaxy HIGH 7.8
CVE-2020-15528

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of we…

Mitigation only
Fix from $1,950 2020-07-05
Galaxy HIGH 7.8
CVE-2020-15529

An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repa…

Mitigation only
Fix from $1,950 2020-07-05
Hylafax\+ HIGH 7.8
CVE-2020-15397

HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations und…

Fix: after 7.0.2
Fix from $1,950 2020-06-30
Sigma Spectrum Infusion System Firmware CRITICAL 9.4
CVE-2020-12041

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM th…

Mitigation only
Fix from $2,300 2020-06-29
Mattermost Server MEDIUM 5.3
CVE-2017-18916

An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res…

Fix: 3.6.7 / 3.7.5+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2016-11062

An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

Fix: 3.5.1+
Fix from $1,600 2020-06-19
Mattermost Server MEDIUM 5.3
CVE-2017-18896

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio…

Fix: 4.0.5 / 4.1.1+
Fix from $1,600 2020-06-19
Mattermost Server HIGH 8.8
CVE-2017-18886

An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands.

Fix: 4.1.2 / 4.2.1+
Fix from $1,950 2020-06-19
Mattermost Server HIGH 8.1
CVE-2017-18894

An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au…

Fix: 4.0.5 / 4.1.1+
Fix from $1,950 2020-06-19
Mattermost Desktop MEDIUM 5.3
CVE-2018-21265

An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, au…

Fix: 4.0.0+
Fix from $1,600 2020-06-19
Ansible Tower MEDIUM 6.5
CVE-2020-10782

An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable …

Mitigation only
Fix from $1,600 2020-06-18
Tcp\/ip MEDIUM 5.3
CVE-2020-11911

The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control.

Fix: 6.0.1.66+
Fix from $1,600 2020-06-17
I2p HIGH 7.8
CVE-2020-13431

I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% su…

Fix: 0.9.46+
Fix from $1,950 2020-06-16
Encryption HIGH 7.8
CVE-2020-5358

Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to inc…

Fix: 2.7+
Fix from $1,950 2020-06-15
Endpoint Agents HIGH 7.8
CVE-2020-5755

Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attac…

Fix: 9.0.28.48+
Fix from $1,950 2020-06-15
Horizon Client HIGH 7.8
CVE-2020-3961

VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe lo…

Fix: 5.4.3+
Fix from $1,950 2020-06-15
Mids\' Reborn Hero Designer HIGH 7.8
CVE-2020-11613

Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation…

No fix yet
Fix from $1,950 2020-06-11
Windows Defender HIGH 7.8
CVE-2020-1170

An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an …

Patch available
Fix from $1,950 2020-06-09
Wingate HIGH 7.8
CVE-2020-13866

WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable f…

No fix yet
Fix from $1,950 2020-06-08
Advanced Monitoring Agent HIGH 7.3
CVE-2020-13912

SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to …

Fix: 10.8.9+
Fix from $1,950 2020-06-07
Smartdraw 2020 HIGH 7.3
CVE-2020-13386

In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folde…

No fix yet
Fix from $1,950 2020-05-27
Software Updater MEDIUM 6.6
CVE-2020-12431

A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and nam…

Fix: 1.5.6.16 / 3.3.8.0+
Fix from $1,600 2020-05-21
Free Range Routing MEDIUM 5.3
CVE-2020-12831

An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empt…

Fix: after 7.3.1
Fix from $1,600 2020-05-13
Group Folders HIGH 8.1
CVE-2020-8153

Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.

Fix: 4.0.4+
Fix from $1,950 2020-05-12
Nginx Controller HIGH 7.8
CVE-2020-5895

On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on t…

Fix: 3.4.0+
Fix from $1,950 2020-05-07
Secure Firewall Management Center HIGH 7.5
CVE-2020-3312

A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,950 2020-05-06
It Installer HIGH 8.1
CVE-2020-11443

The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an update…

Fix: 4.6.10+
Fix from $1,950 2020-05-04