Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Java Sdk HIGH 8.1
CVE-2018-1417

Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manag…

Mitigation only
Fix from $1,950 2018-02-22
Npm HIGH 7.8
CVE-2018-7408

An issue was discovered in an npm 5.7.0 2018-02-21 pre-release (marked as "next: 5.7.0" and therefore automatically installed by an "npm upgrade -g n…

Patch available
Fix from $1,950 2018-02-22
Privatevpn HIGH 8.8
CVE-2018-7311

PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability. The software installs a privileged helper tool that runs as the r…

Mitigation only
Fix from $1,950 2018-02-21
P 870h 51 Firmware CRITICAL 9.8
CVE-2018-1164

This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.…

Mitigation only
Fix from $2,300 2018-02-21
Sys600 Firmware HIGH 7.8
CVE-2018-1168

This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must fi…

Mitigation only
Fix from $1,950 2018-02-21
Shadow MEDIUM 5.3
CVE-2018-7169

An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where s…

No fix yet
Fix from $1,600 2018-02-15
Android HIGH 7.8
CVE-2017-13236

In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to local escalation of privilege wi…

No fix yet
Fix from $1,950 2018-02-12
Firebase Admin Sdk For Php HIGH 8.1
CVE-2018-1000025

Jerome Gamez Firebase Admin SDK for PHP version from 3.2.0 to 3.8.0 contains a Incorrect Access Control vulnerability in src/Firebase/Auth/IdTokenVer…

Fix: after 3.8.0
Fix from $1,950 2018-02-09
PostgreSQL HIGH 7.0
CVE-2018-1053

In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in curr…

Fix: 9.3.21 / 9.4.16+
Fix from $1,950 2018-02-09
Antimalware HIGH 7.8
CVE-2018-6606

An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to r…

No fix yet
Fix from $1,950 2018-02-04
Antimalware HIGH 7.8
CVE-2018-6593

An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged process to r…

No fix yet
Fix from $1,950 2018-02-03
Icinga MEDIUM 5.5
CVE-2018-6536

An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which mi…

Fix: after 2.8.1
Fix from $1,600 2018-02-02
Arq HIGH 7.8
CVE-2017-16928

The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via a cra…

Fix: after 5.10
Fix from $1,950 2018-01-31
Arq HIGH 7.8
CVE-2017-16945

The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently gain root privileges via …

Fix: after 5.10
Fix from $1,950 2018-01-31
Speaks\! HIGH 8.8
CVE-2017-1000403

Jenkins Speaks! Plugin, all current versions, allows users with Job/Configure permission to run arbitrary Groovy code inside the Jenkins JVM, effecti…

Fix: after 0.1.1
Fix from $1,950 2018-01-26
Industrial Ethernet 4010 Series Firmware MEDIUM 6.7
CVE-2018-0088

A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow a…

Mitigation only
Fix from $1,600 2018-01-18
Policy Suite HIGH 7.5
CVE-2018-0089

A vulnerability in the Policy and Charging Rules Function (PCRF) of the Cisco Policy Suite (CPS) could allow an unauthenticated, remote attacker to a…

Mitigation only
Fix from $1,950 2018-01-18
Lm53q1 Firmware CRITICAL 9.8
CVE-2017-16885EPSS 33%

Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usage, Chan…

No fix yet
Fix from $2,300 2018-01-12
Iopsys HIGH 8.8
CVE-2017-17867EPSS 11%

Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the o…

Fix: after 3.14
Fix from $1,950 2018-01-04
Windows 10 HIGH 7.8
CVE-2018-0752

The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Win…

Patch available
Fix from $1,950 2018-01-04
Nylas Mail HIGH 7.8
CVE-2017-1000485

Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via stand…

Mitigation only
Fix from $1,950 2018-01-03
Cnpilot R190v Firmware HIGH 8.8
CVE-2017-5260EPSS 8%

In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration file is not available in the nor…

Fix: after 4.3.2-r4
Fix from $1,950 2017-12-20
Security Guardium MEDIUM 5.4
CVE-2017-1266

IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by uninte…

Mitigation only
Fix from $1,600 2017-12-20
Gpweb CRITICAL 9.8
CVE-2017-15877

Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.

No fix yet
Fix from $2,300 2017-12-19
Posty Readymade Classifieds HIGH 7.5
CVE-2017-17568

Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the backend PHP script), which might…

No fix yet
Fix from $1,950 2017-12-13
Ubuntu Linux HIGH 7.8
CVE-2017-13168

An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android ID A-65023233.

No fix yet
Fix from $1,950 2017-12-06
Arq HIGH 7.8
CVE-2017-16895

The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper apps in Arq 5.x before 5.10 …

Fix: 5.10+
Fix from $1,950 2017-12-01
Icinga HIGH 7.0
CVE-2017-16933

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gai…

Fix: after 2.8.0
Fix from $1,950 2017-11-24
Fusioncompute MEDIUM 6.5
CVE-2017-8158

FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settings for a certain file on the …

Mitigation only
Fix from $1,600 2017-11-22
Icinga HIGH 7.8
CVE-2017-16882

Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account…

Fix: after 1.14.0
Fix from $1,950 2017-11-18