Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Debian Linux HIGH 8.8
CVE-2019-18422

An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Jboss Operations Network HIGH 8.0
CVE-2010-0737

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u…

Fix: 2.3.1+
Fix from $1,950 2019-10-30
Drbd8 HIGH 7.8
CVE-2010-0747

drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.

No fix yet
Fix from $1,950 2019-10-30
Chrome CRITICAL 9.1
CVE-2016-5202

browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 …

Fix: 54.0.2840.98 / 54.0.2840.99+
Fix from $2,300 2019-10-25
Ruby Parser Legacy HIGH 7.8
CVE-2019-18409

The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakema…

No fix yet
Fix from $1,950 2019-10-24
Guix HIGH 7.8
CVE-2019-18192

GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world…

Patch available
Fix from $1,950 2019-10-17
Download Manager CRITICAL 9.8
CVE-2019-8071

Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.

Mitigation only
Fix from $2,300 2019-10-17
Smart Connect Technology HIGH 7.8
CVE-2019-11167

Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially …

Mitigation only
Fix from $1,950 2019-10-11
Uagate Si Firmware HIGH 7.5
CVE-2019-11528

An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.

No fix yet
Fix from $1,950 2019-10-10
Uagate Si Firmware CRITICAL 9.8
CVE-2019-11526

An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This e…

No fix yet
Fix from $2,300 2019-10-10
Windows 10 Update Assistant HIGH 7.8
CVE-2019-1378

An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker coul…

Patch available
Fix from $1,950 2019-10-10
Emc Avamar Server HIGH 8.1
CVE-2019-3765

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2…

Fix: after 2.4
Fix from $1,950 2019-10-09
Junos HIGH 7.1
CVE-2019-0073

The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file permissions. This may allow ano…

Mitigation only
Fix from $1,950 2019-10-09
Enterprise Linux MEDIUM 5.3
CVE-2019-6465

Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 …

Fix: after 9.13.6
Fix from $1,600 2019-10-09
Child Theme Creator MEDIUM 6.5
CVE-2015-9456

The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php…

Fix: 1.2.8+
Fix from $1,600 2019-10-07
Evernote HIGH 7.8
CVE-2019-17051

Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated b…

Fix: 7.13+
Fix from $1,950 2019-09-30
Android HIGH 7.8
CVE-2019-9378

In the Activity Manager service, there is a possible permission bypass due to incorrect permission check. This could lead to local escalation of priv…

Mitigation only
Fix from $1,950 2019-09-27
Silverstripe MEDIUM 5.3
CVE-2019-12245

SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a f…

Fix: after 4.3.3
Fix from $1,600 2019-09-25
Anti Virus HIGH 7.8
CVE-2019-13355

In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.ex…

No fix yet
Fix from $1,950 2019-09-24
Anti Virus HIGH 7.8
CVE-2019-13356

In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT…

No fix yet
Fix from $1,950 2019-09-24
Control For Beaglebone HIGH 8.8
CVE-2019-9008

An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.

Fix: 3.5.13.0+
Fix from $1,950 2019-09-17
GitLab MEDIUM 5.4
CVE-2019-15721

An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainer…

Fix: 12.0.8 / 12.1.8+
Fix from $1,600 2019-09-16
Easy Streaming Wizard MEDIUM 6.7
CVE-2019-11166

Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially …

Fix: 2.1.0731+
Fix from $1,600 2019-09-16
Limesurvey HIGH 7.5
CVE-2019-16187

Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side scrip…

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Horizon Cardiology Firmware HIGH 7.8
CVE-2018-18630

A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker w…

Fix: after 12.2
Fix from $1,950 2019-09-06
Jabber HIGH 7.8
CVE-2019-12645

A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authent…

Fix: 12.6+
Fix from $1,950 2019-09-05
Docker HIGH 7.8
CVE-2019-15752 KEVEPSS 32%

Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in…

Fix: 2.1.0.1+
Fix from $1,950 2019-08-28
Steam Client HIGH 7.8
CVE-2019-15315

Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current ve…

Fix: after 2019-08-16
Fix from $1,950 2019-08-21
Steam Client HIGH 7.0
CVE-2019-15316

Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted u…

Fix: after 2019-08-20
Fix from $1,950 2019-08-21
Silvershield HIGH 7.8
CVE-2019-13069

extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverS…

Fix: after 6.1.14.144
Fix from $1,950 2019-08-17