Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Creative Cloud CRITICAL 9.8
CVE-2019-7958

Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lea…

Fix: after 4.6.1
Fix from $2,300 2019-08-16
Nps MEDIUM 5.5
CVE-2019-15119

lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a …

Fix: after 0.23.2
Fix from $1,600 2019-08-16
Waves Maxx Audio HIGH 7.8
CVE-2019-15084

Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate…

No fix yet
Fix from $1,950 2019-08-16
Cloudvision Portal MEDIUM 6.5
CVE-2018-12357

Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.

Fix: after 2018.1.1
Fix from $1,600 2019-08-15
Enable Now HIGH 8.8
CVE-2019-0341

The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a…

Mitigation only
Fix from $1,950 2019-08-14
Altools HIGH 7.8
CVE-2019-12808

ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can over…

Fix: after 18.1
Fix from $1,950 2019-08-13
Auditor HIGH 7.8
CVE-2019-14969

Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service …

Fix: 9.8+
Fix from $1,950 2019-08-12
3cx HIGH 7.8
CVE-2019-14935

3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control a…

No fix yet
Fix from $1,950 2019-08-12
Adaptive Security Appliance Software HIGH 7.3
CVE-2019-1944

Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to…

Fix: 9.4.4.37+
Fix from $1,950 2019-08-07
Steam Client MEDIUM 6.6
CVE-2019-14743

In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which al…

Fix: after 2019-08-07
Fix from $1,600 2019-08-07
Application Service HIGH 7.5
CVE-2019-11270

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by…

Fix: 2.3.15 / 2.3.22+
Fix from $1,950 2019-08-05
Cpanel MEDIUM 5.4
CVE-2018-20905

cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429).

Fix: 62.0.47 / 68.0.39+
Fix from $1,600 2019-08-01
Cpanel MEDIUM 5.5
CVE-2018-20908

cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435).

Fix: 62.0.47 / 68.0.39+
Fix from $1,600 2019-08-01
Cpanel HIGH 7.1
CVE-2018-20909

cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338).

Fix: 62.0.42 / 68.0.33+
Fix from $1,950 2019-08-01
Grid Engine CRITICAL 9.8
CVE-2018-20871

In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) oc…

Mitigation only
Fix from $2,300 2019-07-30
Qradar Security Information And Event Manager HIGH 8.1
CVE-2018-2024

IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unint…

Patch available
Fix from $1,950 2019-07-22
Rufus CRITICAL 9.8
CVE-2019-1010101

Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The…

Fix: after 3.0
Fix from $2,300 2019-07-19
Honor Magic 2 Firmware MEDIUM 5.5
CVE-2019-5222

There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R…

Mitigation only
Fix from $1,600 2019-07-17
Manageengine Admanager Plus HIGH 7.3
CVE-2019-12876

Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio…

No fix yet
Fix from $1,950 2019-07-17
Dglux Server CRITICAL 9.8
CVE-2019-1010009

DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT …

Mitigation only
Fix from $2,300 2019-07-15
Private Internet Access Vpn Client HIGH 7.8
CVE-2019-12577

A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run …

No fix yet
Fix from $1,950 2019-07-11
Surround MEDIUM 5.5
CVE-2019-13142

The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located …

Mitigation only
Fix from $1,600 2019-07-09
Waves Maxx Audio HIGH 7.3
CVE-2019-13208

WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to …

No fix yet
Fix from $1,950 2019-07-03
Odoo MEDIUM 6.5
CVE-2018-14861

Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of …

Patch available
Fix from $1,600 2019-07-03
Odoo MEDIUM 6.5
CVE-2018-14862

Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated i…

Patch available
Fix from $1,600 2019-07-03
Lgate 902 Firmware CRITICAL 9.1
CVE-2018-14916EPSS 17%

LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.

Fix: 6.4.2+
Fix from $2,300 2019-06-28
Glib HIGH 7.5
CVE-2019-13012

The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL,…

Fix: 2.59.1+
Fix from $1,950 2019-06-28
Android HIGH 7.8
CVE-2019-2023

In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could al…

Mitigation only
Fix from $1,950 2019-06-19
Manageengine Analytics Plus HIGH 7.8
CVE-2019-12133

Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a…

Mitigation only
Fix from $1,950 2019-06-18
Foxit Pdf Sdk Activex HIGH 7.8
CVE-2018-19446

A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataOb…

Fix: after 5.5.0
Fix from $1,950 2019-06-17