Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Chrome MEDIUM 6.5
CVE-2018-18352

Service works could inappropriately gain access to cross origin audio in Media in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to by…

Fix: 71.0.3578.80+
Fix from $1,600 2018-12-11
True Key HIGH 7.8
CVE-2018-6755

Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbit…

Fix: after 5.1.230.7
Fix from $1,950 2018-12-06
5n2 Firmware CRITICAL 9.8
CVE-2018-14703

Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retr…

No fix yet
Fix from $2,300 2018-12-03
Metinfo MEDIUM 6.1
CVE-2018-19836

In Metinfo 6.1.3, include/interface/applogin.php allows setting arbitrary HTTP headers (including the Cookie header), and common.inc.php allows regis…

No fix yet
Fix from $1,600 2018-12-03
Android HIGH 7.5
CVE-2018-15835

Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

Fix: after 9.0
Fix from $1,950 2018-11-30
Openmanage Network Manager MEDIUM 6.5
CVE-2018-15768EPSS 9%

Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configur…

Fix: 6.5.0+
Fix from $1,600 2018-11-30
Pulse Secure Desktop Client MEDIUM 5.5
CVE-2018-11002

Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.

No fix yet
Fix from $1,600 2018-11-29
Terramaster Operating System MEDIUM 6.5
CVE-2018-13355

Incorrect access controls in ajaxdata.php in TerraMaster TOS version 3.1.03 allow attackers to create user groups without proper authorization.

No fix yet
Fix from $1,600 2018-11-27
Android HIGH 7.8
CVE-2018-11914

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11907

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11908

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11909

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11910

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper access control can lead to device…

Patch available
Fix from $1,950 2018-11-27
Android HIGH 7.8
CVE-2018-11913

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may le…

Patch available
Fix from $1,950 2018-11-27
Ts5600d1206 Firmware HIGH 8.8
CVE-2018-13321

Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "method" pa…

No fix yet
Fix from $1,950 2018-11-26
Accu Chek Inform Ii Firmware HIGH 8.0
CVE-2018-18561

An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 0…

Fix: 03.01.04+
Fix from $1,950 2018-11-20
Trio 8500 Firmware MEDIUM 6.5
CVE-2018-14934

The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authenticati…

Fix: 5.5.4+
Fix from $1,600 2018-11-15
Chrome HIGH 8.8
CVE-2018-6057

Lack of special casing of Android ashmem in Google Chrome prior to 65.0.3325.146 allowed a remote attacker who had compromised the renderer process t…

Fix: 65.0.3325.146+
Fix from $1,950 2018-11-14
Media Server Studio HIGH 7.8
CVE-2018-3697

Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of…

Mitigation only
Fix from $1,950 2018-11-14
Fiori Client HIGH 7.8
CVE-2018-2489

Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.…

Fix: 1.11.5+
Fix from $1,950 2018-11-13
Fiori Client HIGH 7.8
CVE-2018-2490

The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses …

Fix: 1.11.5+
Fix from $1,950 2018-11-13
I5 Application Firmware HIGH 7.8
CVE-2018-19071

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,950 2018-11-07
I5 Application Firmware MEDIUM 5.5
CVE-2018-19072

An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Fir…

No fix yet
Fix from $1,600 2018-11-07
Openstack MEDIUM 5.5
CVE-2016-2121

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive informat…

Mitigation only
Fix from $1,600 2018-10-31
A Tuning HIGH 7.8
CVE-2018-10709

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Rest…

Fix: 1.0.6.2 / 1.0.35.1+
Fix from $1,950 2018-10-30
A Tuning HIGH 7.1
CVE-2018-10710

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Rest…

Fix: 1.0.6.2 / 1.0.35.1+
Fix from $1,950 2018-10-30
A Tuning HIGH 7.8
CVE-2018-10712

The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and Rest…

Fix: 1.0.6.2 / 1.0.35.1+
Fix from $1,950 2018-10-30
Sd 845 Firmware MEDIUM 5.5
CVE-2018-11951

Improper access control in core module lead XBL_LOADER performs the ZI region clear for QTEE instead of XBL_SEC in Snapdragon Mobile in version SD 84…

Mitigation only
Fix from $1,600 2018-10-26
Crossroads HIGH 7.8
CVE-2018-18654

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in …

Mitigation only
Fix from $1,950 2018-10-26
Impala CRITICAL 9.8
CVE-2018-11792

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER…

Fix: 3.0.1+
Fix from $2,300 2018-10-24