Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Synapse HIGH 8.4
CVE-2017-11652

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Troja…

Fix: after 2.20.15.1104
Fix from $1,950 2017-08-18
Synapse HIGH 7.8
CVE-2017-11653

Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan hors…

Fix: after 2.20.15.1104
Fix from $1,950 2017-08-18
Xamarin.ios HIGH 7.8
CVE-2017-8665

The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege V…

Fix: after 10.11
Fix from $1,950 2017-08-15
Download Station HIGH 7.8
CVE-2017-11156

Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows re…

Mitigation only
Fix from $1,950 2017-08-14
GitLab MEDIUM 6.5
CVE-2017-11437

GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to us…

Mitigation only
Fix from $1,600 2017-08-02
Dpc3939 Firmware CRITICAL 9.8
CVE-2017-9479

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitr…

No fix yet
Fix from $2,300 2017-07-31
Dpc3939 Firmware CRITICAL 9.8
CVE-2017-9482

The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root ac…

No fix yet
Fix from $2,300 2017-07-31
Mx011anm Firmware MEDIUM 5.3
CVE-2017-9494

The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspecto…

Mitigation only
Fix from $1,600 2017-07-31
Statamic HIGH 8.8
CVE-2017-11422

Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods…

Fix: 2.6.0+
Fix from $1,950 2017-07-24
Logicaldoc HIGH 8.8
CVE-2017-1000022

LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation.

Fix: after 7.5.3
Fix from $1,950 2017-07-17
Android HIGH 7.8
CVE-2017-0703

A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Andr…

Mitigation only
Fix from $1,950 2017-07-06
Moneyworks CRITICAL 9.8
CVE-2017-9615

Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging…

Fix: after 8.0.3
Fix from $2,300 2017-06-26
Debian Linux HIGH 7.8
CVE-2017-9780

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example set…

Fix: after 0.8.6
Fix from $1,950 2017-06-21
X Pack MEDIUM 5.9
CVE-2017-8449

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl…

Fix: after 5.2.2
Fix from $1,600 2017-06-16
X Pack HIGH 7.5
CVE-2017-8450

X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an…

Mitigation only
Fix from $1,950 2017-06-16
Kbvault Mysql CRITICAL 9.8
CVE-2017-9602

KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthe…

No fix yet
Fix from $2,300 2017-06-16
Vipnet Client HIGH 7.3
CVE-2017-9606

Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the up…

Fix: after 4.3.1
Fix from $1,950 2017-06-15
Trusted Firmware A HIGH 8.1
CVE-2017-7563

In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mecha…

Fix: after 1.3
Fix from $1,950 2017-06-07
Debian Linux HIGH 8.8
CVE-2017-9462EPSS 22%

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary cod…

Fix: 4.1.3+
Fix from $1,950 2017-06-06
Fortiportal CRITICAL 9.1
CVE-2017-7337

An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or e…

Fix: after 4.0.0
Fix from $2,300 2017-05-27
Backhaul Radios HIGH 7.5
CVE-2017-9136

An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsani…

Fix: after 2.2.1
Fix from $1,950 2017-05-21
Debian Linux HIGH 7.8
CVE-2017-7493

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control…

Fix: after 2.9.1
Fix from $1,950 2017-05-17
Android HIGH 7.8
CVE-2017-0593

An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This…

Patch available
Fix from $1,950 2017-05-12
Android MEDIUM 5.5
CVE-2017-0601

An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via blueto…

Patch available
Fix from $1,600 2017-05-12
Gpu Driver HIGH 7.8
CVE-2017-0352

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the GPU firmware where incorrect access control may allow CPU access sensiti…

Mitigation only
Fix from $1,950 2017-05-09
Netbackup CRITICAL 9.8
CVE-2017-8856

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the …

Fix: after 8.0
Fix from $2,300 2017-05-09
Netbackup CRITICAL 9.8
CVE-2017-8857EPSS 6%

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command executi…

Fix: after 8.0
Fix from $2,300 2017-05-09
Netbackup CRITICAL 9.8
CVE-2017-8858

In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' …

Fix: after 8.0
Fix from $2,300 2017-05-09
Client Automation MEDIUM 5.5
CVE-2017-8391

The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file …

Mitigation only
Fix from $1,600 2017-05-06
Nessus MEDIUM 5.5
CVE-2017-7849

Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.

Mitigation only
Fix from $1,600 2017-04-19