Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Nessus HIGH 7.8
CVE-2017-7850

Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.

Mitigation only
Fix from $1,950 2017-04-19
Linux Kernel HIGH 7.8
CVE-2017-7889

The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to…

Fix: 3.2.91 / 3.10.107+
Fix from $1,950 2017-04-17
Creative Cloud HIGH 8.8
CVE-2017-3006EPSS 11%

Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creativ…

Fix: after 3.9.5.353
Fix from $1,950 2017-04-12
Nextcloud Server MEDIUM 6.4
CVE-2017-0883

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the O…

Fix: after 9.0.54
Fix from $1,600 2017-04-05
Interscan Web Security Virtual Appliance MEDIUM 6.5
CVE-2017-6338

Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user…

Fix: after 6.5
Fix from $1,600 2017-04-05
Rios MEDIUM 6.8
CVE-2017-7307

Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to o…

Fix: after 9.0.0b
Fix from $1,600 2017-04-04
Log And Event Manager HIGH 8.8
CVE-2017-5199

The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/c…

Fix: after 6.3.1
Fix from $1,950 2017-03-24
Gui For Windows CRITICAL 9.8
CVE-2017-6950

SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a…

Mitigation only
Fix from $2,300 2017-03-23
Nessus HIGH 7.8
CVE-2017-7199

Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is run…

Mitigation only
Fix from $1,950 2017-03-23
Terminal Services Agent MEDIUM 5.3
CVE-2017-6356

Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows atta…

Mitigation only
Fix from $1,600 2017-03-20
Mcollective Puppet Agent HIGH 8.8
CVE-2017-2290

On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu…

Mitigation only
Fix from $1,950 2017-03-03
Zen Mobile App Native HIGH 7.5
CVE-2017-6104EPSS 7%

Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.

Fix: after 3.0
Fix from $1,950 2017-03-02
Gpu Driver HIGH 8.8
CVE-2017-0311

NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service …

Mitigation only
Fix from $1,950 2017-02-15
Gpu Driver HIGH 7.5
CVE-2017-0317

All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extractio…

Mitigation only
Fix from $1,950 2017-02-15
Android MEDIUM 5.3
CVE-2017-0423

An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rat…

Mitigation only
Fix from $1,600 2017-02-08
Chrome HIGH 7.5
CVE-2013-0885

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interac…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,950 2013-02-23
Chrome HIGH 7.5
CVE-2013-0887

The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restric…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,950 2013-02-23
Email Gateway MEDIUM 6.5
CVE-2010-2116

The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privi…

No fix yet
Fix from $1,600 2010-05-28
Internet Explorer MEDIUM 6.5
CVE-2010-0488EPSS 29%

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas…

Patch available
Fix from $1,600 2010-03-31
Dovecot MEDIUM 5.5
CVE-2009-3897

Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbi…

Fix: 1.2.8+
Fix from $1,600 2009-11-24
Linux Kernel HIGH 7.1
CVE-2009-3939

The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t…

Fix: after 2.6.31.6
Fix from $1,950 2009-11-16
Fedora HIGH 7.1
CVE-2009-3611

common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, …

Patch available
Fix from $1,950 2009-10-26
Antivirus HIGH 7.8
CVE-2009-3482

TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%,…

Fix: 2.0.0.1291 / 2.8.0.2266+
Fix from $1,950 2009-09-30
Photoshop Elements HIGH 7.8
CVE-2009-3489

Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) …

No fix yet
Fix from $1,950 2009-09-30
Glib HIGH 7.8
CVE-2009-3289

The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted lo…

No fix yet
Fix from $1,950 2009-09-22
Nss Ldap MEDIUM 5.5
CVE-2009-1073

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for …

Fix: 0.6.8+
Fix from $1,600 2009-03-31
Fedora HIGH 7.8
CVE-2009-0115

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server …

Fix: after 11.0
Fix from $1,950 2009-03-30
Mac Os X MEDIUM 5.5
CVE-2009-0141

XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local use…

Mitigation only
Fix from $1,600 2009-02-13
Vpn 1 Secureclient HIGH 7.8
CVE-2008-0662

The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRem…

Mitigation only
Fix from $1,950 2008-02-08
Intouch HIGH 8.8
CVE-2007-6033

Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers…

Mitigation only
Fix from $1,950 2007-11-20