Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Licensing Service HIGH 7.1
CVE-2019-19315

NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nl…

No fix yet
Fix from $1,950 2019-12-17
Android MEDIUM 5.5
CVE-2019-9464

In various functions of RecentLocationApps.java, DevicePolicyManagerService.java, and RecognitionService.java, there is an incorrect warning indicati…

Patch available
Fix from $1,600 2019-12-06
Vpn Client HIGH 7.8
CVE-2019-17388

Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute…

Fix: after 2.2.10
Fix from $1,950 2019-12-05
Debian Linux MEDIUM 5.5
CVE-2013-0326

OpenStack nova base images permissions are world readable

Mitigation only
Fix from $1,600 2019-12-05
OpenBSD HIGH 7.8
CVE-2019-19522

OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging members…

No fix yet
Fix from $1,950 2019-12-05
Anti Virus Plus HIGH 7.8
CVE-2019-19382

Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achi…

No fix yet
Fix from $1,950 2019-12-03
P20 Firmware MEDIUM 5.5
CVE-2019-5212

There is an improper access control vulnerability in Huawei Share. The software does not properly restrict access to certain file from certain applic…

Mitigation only
Fix from $1,600 2019-11-29
Debian Linux MEDIUM 5.3
CVE-2011-2515

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…

Mitigation only
Fix from $1,600 2019-11-27
Fedora HIGH 7.8
CVE-2019-14812

A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls,…

Fix: 9.50+
Fix from $1,950 2019-11-27
GitLab MEDIUM 5.3
CVE-2019-18452

An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It …

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 5.3
CVE-2019-18456

An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It…

Fix: after 12.4.0
Fix from $1,600 2019-11-26
GitLab MEDIUM 5.3
CVE-2019-18459

An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (i…

Fix: after 12.3.0
Fix from $1,600 2019-11-26
Chrome MEDIUM 6.5
CVE-2019-13665

Insufficient filtering in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass multiple file download protection via a cr…

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Chrome MEDIUM 6.5
CVE-2019-13677

Insufficient policy enforcement in site isolation in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to bypass site isolation via a cra…

Fix: 77.0.3865.75+
Fix from $1,600 2019-11-25
Kyrol Internet Security HIGH 7.8
CVE-2019-19197

IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and …

No fix yet
Fix from $1,950 2019-11-21
Centreon Web HIGH 7.8
CVE-2019-16406

Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attack…

Patch available
Fix from $1,950 2019-11-21
Nitro Pro HIGH 7.8
CVE-2019-18958

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation o…

Fix: 13.2+
Fix from $1,950 2019-11-21
Fedora HIGH 8.8
CVE-2019-14869

A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged cal…

Fix: 9.50+
Fix from $1,950 2019-11-15
Proset\/wireless Wifi HIGH 7.1
CVE-2019-11154

Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable d…

Fix: 21.40+
Fix from $1,950 2019-11-14
Proset\/wireless Wifi HIGH 7.1
CVE-2019-11155

Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable d…

Fix: 21.40+
Fix from $1,950 2019-11-14
Scanguard Antivirus HIGH 7.8
CVE-2019-18895

Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse e…

Fix: after 2019-11-12
Fix from $1,950 2019-11-14
Office HIGH 7.8
CVE-2019-1457

A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Offi…

Patch available
Fix from $1,950 2019-11-12
Svg Sanitizer HIGH 7.5
CVE-2019-18856

A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an S…

Fix: after 7.x-1.5
Fix from $1,950 2019-11-11
Zxupn 9000e Firmware HIGH 8.8
CVE-2019-3425

The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An at…

Fix: 9000ev5.0r1b12+
Fix from $1,950 2019-11-08
Enterprise Linux MEDIUM 6.5
CVE-2019-14824

A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations,…

Mitigation only
Fix from $1,600 2019-11-08
Openstack Mistral MEDIUM 5.5
CVE-2019-3866

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world…

Mitigation only
Fix from $1,600 2019-11-08
Debian Linux HIGH 7.5
CVE-2007-5743

viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

No fix yet
Fix from $1,950 2019-11-07
Impala HIGH 7.5
CVE-2019-10084

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o…

Fix: after 3.2.0
Fix from $1,950 2019-11-05
Ovirt Engine HIGH 7.8
CVE-2013-4367

ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how pyth…

Patch available
Fix from $1,950 2019-11-01
Struts CRITICAL 9.8
CVE-2011-3923EPSS 88%

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

Fix: 2.3.1.2+
Fix from $2,300 2019-11-01