Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2020-11827 In GOG Galaxy 1.2.67, there is a service that is vulnerable to weak file/service permissions: GalaxyClientService.exe. An attacker can put malicious … Galaxy 1.2.67+ Fix from $1,9502020-07-14 MEDIUM 5.4 CVE-2020-6267 Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only flag. Disclosure Management Mitigation only Fix from $1,6002020-07-14 HIGH 8.8 CVE-2020-5371 Dell EMC Isilon OneFS versions 8.2.2 and earlier and Dell EMC PowerScale version 9.0.0 contain a file permissions vulnerability. An attacker, with ne… Emc Isilon Onefs after 8.2.2 Fix from $1,9502020-07-06 HIGH 7.8 CVE-2020-15528 An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user starts or uninstalls a game because of we… Galaxy Mitigation only Fix from $1,9502020-07-05 HIGH 7.8 CVE-2020-15529 An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repa… Galaxy Mitigation only Fix from $1,9502020-07-05 HIGH 7.8 CVE-2020-15397 HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations und… Hylafax\+ after 7.0.2 Fix from $1,9502020-06-30 CRITICAL 9.4 CVE-2020-12041 The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM th… Sigma Spectrum Infusion System Firmware Mitigation only Fix from $2,3002020-06-29 MEDIUM 5.3 CVE-2017-18916 An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. API endpoint access control does not honor an integration permission res… Mattermost Server 3.6.7 / 3.7.5+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2016-11062 An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed. Mattermost Server 3.5.1+ Fix from $1,6002020-06-19 MEDIUM 5.3 CVE-2017-18896 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It allows attackers to add DEBUG lines to the logs via a REST API versio… Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,6002020-06-19 HIGH 8.8 CVE-2017-18886 An issue was discovered in Mattermost Server before 4.3.0, 4.2.1, and 4.1.2. It allows a bypass of restrictions on use of slash commands. Mattermost Server 4.1.2 / 4.2.1+ Fix from $1,9502020-06-19 HIGH 8.1 CVE-2017-18894 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5, when used as an OAuth 2.0 service provider. Sometimes. resource-owner au… Mattermost Server 4.0.5 / 4.1.1+ Fix from $1,9502020-06-19 MEDIUM 5.3 CVE-2018-21265 An issue was discovered in Mattermost Desktop App before 4.0.0. It mishandled the Same Origin Policy for setPermissionRequestHandler (e.g., video, au… Mattermost Desktop 4.0.0+ Fix from $1,6002020-06-19 MEDIUM 6.5 CVE-2020-10782 An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable … Ansible Tower Mitigation only Fix from $1,6002020-06-18 MEDIUM 5.3 CVE-2020-11911 The Treck TCP/IP stack before 6.0.1.66 has Improper ICMPv4 Access Control. Tcp\/ip 6.0.1.66+ Fix from $1,6002020-06-17 HIGH 7.8 CVE-2020-13431 I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% su… I2p 0.9.46+ Fix from $1,9502020-06-16 HIGH 7.8 CVE-2020-5358 Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to inc… Encryption 2.7+ Fix from $1,9502020-06-15 HIGH 7.8 CVE-2020-5755 Webroot endpoint agents prior to version v9.0.28.48 did not protect the "%PROGRAMDATA%\WrData\PKG" directory against renaming. This could allow attac… Endpoint Agents 9.0.28.48+ Fix from $1,9502020-06-15 HIGH 7.8 CVE-2020-3961 VMware Horizon Client for Windows (prior to 5.4.3) contains a privilege escalation vulnerability due to folder permission configuration and unsafe lo… Horizon Client 5.4.3+ Fix from $1,9502020-06-15 HIGH 7.8 CVE-2020-11613 Mids' Reborn Hero Designer 2.6.0.7 has an elevation of privilege vulnerability due to default and insecure permissions being set for the installation… Mids\' Reborn Hero Designer No fix yet Fix from $1,9502020-06-11 HIGH 7.8 CVE-2020-1170 An elevation of privilege vulnerability exists in Windows Defender that leads arbitrary file deletion on the system.To exploit the vulnerability, an … Windows Defender Patch available Fix from $1,9502020-06-09 HIGH 7.8 CVE-2020-13866 WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable f… Wingate No fix yet Fix from $1,9502020-06-08 HIGH 7.3 CVE-2020-13912 SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to … Advanced Monitoring Agent 10.8.9+ Fix from $1,9502020-06-07 HIGH 7.3 CVE-2020-13386 In SmartDraw 2020 27.0.0.0, the installer gives inherited write permissions to the Authenticated Users group on the SmartDraw 2020 installation folde… Smartdraw 2020 No fix yet Fix from $1,9502020-05-27 MEDIUM 6.6 CVE-2020-12431 A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and nam… Software Updater 1.5.6.16 / 3.3.8.0+ Fix from $1,6002020-05-21 MEDIUM 5.3 CVE-2020-12831 An issue was discovered in FRRouting FRR (aka Free Range Routing) through 7.3.1. When using the split-config feature, the init script creates an empt… Free Range Routing after 7.3.1 Fix from $1,6002020-05-13 HIGH 8.1 CVE-2020-8153 Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name. Group Folders 4.0.4+ Fix from $1,9502020-05-12 HIGH 7.8 CVE-2020-5895 On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on t… Nginx Controller 3.4.0+ Fix from $1,9502020-05-07 HIGH 7.5 CVE-2020-3312 A vulnerability in the application policy configuration of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attac… Secure Firewall Management Center Mitigation only Fix from $1,9502020-05-06 HIGH 8.1 CVE-2020-11443 The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an update… It Installer 4.6.10+ Fix from $1,9502020-05-04