Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Opencast MEDIUM 6.5
CVE-2017-1000221

In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the …

Fix: after 2.2.3
Fix from $1,600 2017-11-17
Codiad HIGH 7.5
CVE-2017-1000125

Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.

No fix yet
Fix from $1,950 2017-11-17
Android HIGH 7.8
CVE-2017-0830

An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8…

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-0831

An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941.

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.5
CVE-2017-0845

A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1…

Patch available
Fix from $1,950 2017-11-16
Pnp4nagios HIGH 7.8
CVE-2017-16834

PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allow…

Fix: after 0.6.26
Fix from $1,950 2017-11-16
Scala HIGH 7.8
CVE-2017-15288

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-…

Fix: 2.10.7 / 2.11.12+
Fix from $1,950 2017-11-15
Hadoop HIGH 7.8
CVE-2017-3166

In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl…

Mitigation only
Fix from $1,950 2017-11-13
Bolt MEDIUM 5.3
CVE-2017-16754

Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServ…

Fix: after 3.3.5
Fix from $1,600 2017-11-10
Vpn HIGH 7.8
CVE-2017-16757

Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.…

No fix yet
Fix from $1,950 2017-11-09
Anti Spam Smtp Proxy HIGH 7.8
CVE-2017-16659

The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to in…

Fix: after 1.9.8.13030
Fix from $1,950 2017-11-08
Vde CRITICAL 9.8
CVE-2017-16638

The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a di…

Fix: 2.3.2+
Fix from $2,300 2017-11-06
Mahara CRITICAL 9.8
CVE-2017-1000153

Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset li…

Patch available
Fix from $2,300 2017-11-03
Mahara HIGH 8.1
CVE-2017-1000134

Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to …

Patch available
Fix from $1,950 2017-11-03
MariaDB HIGH 7.8
CVE-2017-15945

The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages …

Fix: 5.6.36 / 10.0.30+
Fix from $1,950 2017-10-27
Debian Linux MEDIUM 5.3
CVE-2017-15906

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers …

Fix: 7.6+
Fix from $1,600 2017-10-26
Iphone Os MEDIUM 5.3
CVE-2017-7146

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Security" component. It allows attackers to tra…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Octopus Deploy MEDIUM 6.5
CVE-2017-15611

In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to te…

Fix: after 3.17.6
Fix from $1,600 2017-10-19
Bamboo HIGH 8.8
CVE-2017-9514

Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which c…

Mitigation only
Fix from $1,950 2017-10-12
Script Security MEDIUM 6.5
CVE-2017-1000095

The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S…

Mitigation only
Fix from $1,600 2017-10-05
Pipeline\ HIGH 8.8
CVE-2017-1000096

Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline sc…

Fix: after 2.36
Fix from $1,950 2017-10-05
Impala MEDIUM 6.5
CVE-2017-9792

In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt…

Mitigation only
Fix from $1,600 2017-10-04
U.motion Builder HIGH 7.8
CVE-2017-9958

An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handl…

Fix: after 1.2.1
Fix from $1,950 2017-09-26
Logstash HIGH 7.8
CVE-2017-14730

The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory tre…

Patch available
Fix from $1,950 2017-09-25
India Goods And Services Tax Network Offline Utility Tool HIGH 7.8
CVE-2017-13779

GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offlin…

Fix: after 1.1
Fix from $1,950 2017-09-14
Rhnsd MEDIUM 5.5
CVE-2017-7560

It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes.

Mitigation only
Fix from $1,600 2017-09-13
Android HIGH 8.8
CVE-2017-0784

A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android …

Patch available
Fix from $1,950 2017-09-08
Android HIGH 7.8
CVE-2017-0752

A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.…

Patch available
Fix from $1,950 2017-09-08
Webaccess HIGH 7.8
CVE-2017-12713

An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files …

Fix: after 8.2
Fix from $1,950 2017-08-30
Internet Security CRITICAL 9.8
CVE-2017-12816

In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malwa…

Mitigation only
Fix from $2,300 2017-08-25