Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Wifiranger Firmware HIGH 8.8
CVE-2018-17873

An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacke…

Fix: after 7.0.8
Fix from $1,950 2018-10-23
Splunk HIGH 7.0
CVE-2017-18348

Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by …

Fix: after 6.6.11
Fix from $1,950 2018-10-19
Secure Remote Services HIGH 7.8
CVE-2018-11080

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple c…

Fix: 3.32.00.08+
Fix from $1,950 2018-10-18
Crucible HIGH 7.8
CVE-2018-13399

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak…

Fix: 4.6.1+
Fix from $1,950 2018-10-16
Nuuo Cms HIGH 8.8
CVE-2018-17892

NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to no…

Fix: after 3.1
Fix from $1,950 2018-10-12
Spectrum Lsf MEDIUM 5.3
CVE-2018-1724

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permissio…

Patch available
Fix from $1,600 2018-10-11
Server Board S2600bp Firmware HIGH 7.6
CVE-2018-12173

Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may…

Fix: 00.01.0014+
Fix from $1,950 2018-10-10
Client Nvme HIGH 7.8
CVE-2018-12131

Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticate…

Fix: 4.0.0.1007 / 4.7.0.2083+
Fix from $1,950 2018-10-10
Windows 10 HIGH 7.8
CVE-2018-8411

An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Wind…

Patch available
Fix from $1,950 2018-10-10
End Point Security HIGH 7.8
CVE-2018-17775

Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by rep…

No fix yet
Fix from $1,950 2018-10-08
Security Key Lifecycle Manager HIGH 8.1
CVE-2018-1750

IBM Security Key Lifecycle Manager 3.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modifi…

Fix: after 2.7.0.4
Fix from $1,950 2018-10-08
Emc Unity Operating Environment HIGH 7.8
CVE-2018-11064

Dell EMC Unity OE versions 4.3.0.x and 4.3.1.x and UnityVSA OE versions 4.3.0.x and 4.3.1.x contains an Incorrect File Permissions vulnerability. A l…

Fix: after 4.3.1.1525703027
Fix from $1,950 2018-10-05
Prime Infrastructure CRITICAL 9.8
CVE-2018-15379EPSS 86%

A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticate…

No fix yet
Fix from $2,300 2018-10-05
Webex Meetings Online HIGH 7.3
CVE-2018-0422

A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally s…

Fix: 1.3.37 / 32.15.20+
Fix from $1,950 2018-10-05
Collaboration Compliance HIGH 8.8
CVE-2018-17872

Verba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.

Fix: 9.2.1.5545+
Fix from $1,950 2018-10-04
Geforce Experience HIGH 7.0
CVE-2018-6261

NVIDIA GeForce Experience prior to 3.15 contains a vulnerability when GameStream is enabled which sets incorrect permissions on a file, which may to …

Fix: 3.15+
Fix from $1,950 2018-10-02
Websphere Portal MEDIUM 6.5
CVE-2018-1420

IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 resets access control settings to the out of the box configuration during Combined Cumulative Fix (CF) in…

Patch available
Fix from $1,600 2018-10-01
Antivirus HIGH 7.8
CVE-2018-17776

PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replaci…

No fix yet
Fix from $1,950 2018-09-28
Enterprise Linux Desktop MEDIUM 5.0
CVE-2018-14650

It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool reada…

Patch available
Fix from $1,600 2018-09-27
Ee40vb Firmware HIGH 7.8
CVE-2018-14327

The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak pe…

Patch available
Fix from $1,950 2018-09-26
Shadow HIGH 7.8
CVE-2018-16588

Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux E…

Fix: after 4.5-5.39
Fix from $1,950 2018-09-26
E Alert Firmware HIGH 7.5
CVE-2018-8848

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exp…

Mitigation only
Fix from $1,950 2018-09-26
Chrome MEDIUM 6.5
CVE-2018-6040

Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially bypass content security pol…

Fix: 64.0.3282.119+
Fix from $1,600 2018-09-25
Cn80 MEDIUM 5.8
CVE-2018-14825

On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN…

Mitigation only
Fix from $1,600 2018-09-24
T Router Firmware CRITICAL 9.8
CVE-2018-11240

An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol…

Mitigation only
Fix from $2,300 2018-09-21
Db2 HIGH 7.8
CVE-2018-1711

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to all…

Mitigation only
Fix from $1,950 2018-09-21
Msm8909w Firmware HIGH 7.8
CVE-2018-11277

In Snapdragon (Automobile, Mobile, Wear) in version MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 6…

Mitigation only
Fix from $1,950 2018-09-20
Webcenter Interaction MEDIUM 5.4
CVE-2018-16958

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Servic…

Mitigation only
Fix from $1,600 2018-09-18
Ucms HIGH 8.8
CVE-2018-17037

user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

No fix yet
Fix from $1,950 2018-09-14
Openvino Toolkit HIGH 7.8
CVE-2018-12162

Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code…

Fix: 2018.1.265+
Fix from $1,950 2018-09-12