Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Nx Os HIGH 7.8
CVE-2019-1601

A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a…

Fix: 6.0 / 6.2+
Fix from $1,950 2019-03-08
Nx Os HIGH 7.8
CVE-2019-1596

A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege le…

Fix: 7.0+
Fix from $1,950 2019-03-07
Pfsense HIGH 7.5
CVE-2018-20798

The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, …

Patch available
Fix from $1,950 2019-03-01
Firefox MEDIUM 6.5
CVE-2018-18495

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could…

Fix: 64.0+
Fix from $1,600 2019-02-28
Firefox MEDIUM 6.5
CVE-2018-12396

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential p…

Fix: 60.3 / 63.0+
Fix from $1,600 2019-02-28
Android MEDIUM 5.5
CVE-2019-2001

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. U…

Mitigation only
Fix from $1,600 2019-02-28
Sonicosv MEDIUM 5.5
CVE-2018-9867

In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic…

Fix: after 5.9.1.10
Fix from $1,600 2019-02-19
Data Center Manager MEDIUM 5.5
CVE-2019-0108

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure …

Fix: 5.0.2+
Fix from $1,600 2019-02-18
Data Center Manager MEDIUM 5.5
CVE-2019-0111

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information…

Fix: 5.0.2+
Fix from $1,600 2019-02-18
Control For Beaglebone Sl CRITICAL 9.8
CVE-2018-10612

In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not…

Fix: 3.5.14.0+
Fix from $2,300 2019-01-29
Spotfire Analytics Platform For Aws MEDIUM 5.3
CVE-2018-18812

The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a v…

Fix: after 10.0.0
Fix from $1,600 2019-01-16
Ceph MEDIUM 5.7
CVE-2018-14662

It was found Ceph versions before 13.2.4 that authenticated ceph users with read only permissions could steal dm-crypt encryption keys used in ceph d…

Fix: 13.2.4+
Fix from $1,600 2019-01-15
Securesphere HIGH 8.8
CVE-2018-5413

Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escal…

No fix yet
Fix from $1,950 2019-01-10
Proset\/wireless Software HIGH 7.8
CVE-2018-12177

Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized u…

Fix: 20.90.0.7+
Fix from $1,950 2019-01-10
Sgx Platform Software HIGH 7.3
CVE-2018-18098

Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privil…

Fix: 2.2.100+
Fix from $1,950 2019-01-10
Ssd Data Center Tool HIGH 7.8
CVE-2018-3703

Improper directory permissions in the installer for the Intel(R) SSD Data Center Tool for Windows before v3.0.17 may allow authenticated users to pot…

Fix: 3.0.17+
Fix from $1,950 2019-01-10
Exchange Server MEDIUM 6.5
CVE-2019-0588

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than int…

Patch available
Fix from $1,600 2019-01-08
Code42 HIGH 7.8
CVE-2018-20131

The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log d…

Fix: 6.8.4+
Fix from $1,950 2019-01-03
Mxq Tv Box Firmware HIGH 7.1
CVE-2018-14987

The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework…

Mitigation only
Fix from $1,950 2018-12-28
Douphp MEDIUM 5.3
CVE-2018-20567

An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which insta…

No fix yet
Fix from $1,600 2018-12-28
Officescan HIGH 7.5
CVE-2018-18331

A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the file…

Patch available
Fix from $1,950 2018-12-21
Officescan HIGH 7.5
CVE-2018-18332

A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modi…

Mitigation only
Fix from $1,950 2018-12-21
Android HIGH 7.8
CVE-2018-11964

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd…

Patch available
Fix from $1,950 2018-12-20
Vrealize Operations MEDIUM 6.7
CVE-2018-6978

vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vu…

Fix: 6.6.1.11286876 / 6.7.0.11286837+
Fix from $1,600 2018-12-18
Vtune Amplifier HIGH 7.8
CVE-2018-18093

Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privile…

Fix: after 2018
Fix from $1,950 2018-12-14
Solid State Drive Toolbox HIGH 7.8
CVE-2018-18097

Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of pr…

Fix: 3.5.7+
Fix from $1,950 2018-12-14
Parallel Studio HIGH 7.8
CVE-2018-3704

Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an…

Fix: 2019+
Fix from $1,950 2018-12-14
System Defense Utility MEDIUM 5.5
CVE-2018-3705

Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authenticated users to potentially e…

Mitigation only
Fix from $1,600 2018-12-14
Mosquitto HIGH 7.5
CVE-2018-20145

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and…

Fix: 1.5.5+
Fix from $1,950 2018-12-13
Chrome MEDIUM 6.5
CVE-2018-18349

Remote frame navigations was incorrectly permitted to local resources in Blink in Google Chrome prior to 71.0.3578.80 allowed an attacker who convinc…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11