Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.8 CVE-2019-18422 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous… Debian Linux after 4.12.1 Fix from $1,9502019-10-31 HIGH 8.0 CVE-2010-0737 A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON u… Jboss Operations Network 2.3.1+ Fix from $1,9502019-10-30 HIGH 7.8 CVE-2010-0747 drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725. Drbd8 No fix yet Fix from $1,9502019-10-30 CRITICAL 9.1 CVE-2016-5202 browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 … Chrome 54.0.2840.98 / 54.0.2840.99+ Fix from $2,3002019-10-25 HIGH 7.8 CVE-2019-18409 The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakema… Ruby Parser Legacy No fix yet Fix from $1,9502019-10-24 HIGH 7.8 CVE-2019-18192 GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world… Guix Patch available Fix from $1,9502019-10-17 CRITICAL 9.8 CVE-2019-8071 Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. Download Manager Mitigation only Fix from $2,3002019-10-17 HIGH 7.8 CVE-2019-11167 Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially … Smart Connect Technology Mitigation only Fix from $1,9502019-10-11 HIGH 7.5 CVE-2019-11528 An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable. Uagate Si Firmware No fix yet Fix from $1,9502019-10-10 CRITICAL 9.8 CVE-2019-11526 An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This e… Uagate Si Firmware No fix yet Fix from $2,3002019-10-10 HIGH 7.8 CVE-2019-1378 An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker coul… Windows 10 Update Assistant Patch available Fix from $1,9502019-10-10 HIGH 8.1 CVE-2019-3765 Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2… Emc Avamar Server after 2.4 Fix from $1,9502019-10-09 HIGH 7.1 CVE-2019-0073 The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file permissions. This may allow ano… Junos Mitigation only Fix from $1,9502019-10-09 MEDIUM 5.3 CVE-2019-6465 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 … Enterprise Linux after 9.13.6 Fix from $1,6002019-10-09 MEDIUM 6.5 CVE-2015-9456 The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php… Child Theme Creator 1.2.8+ Fix from $1,6002019-10-07 HIGH 7.8 CVE-2019-17051 Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated b… Evernote 7.13+ Fix from $1,9502019-09-30 HIGH 7.8 CVE-2019-9378 In the Activity Manager service, there is a possible permission bypass due to incorrect permission check. This could lead to local escalation of priv… Android Mitigation only Fix from $1,9502019-09-27 MEDIUM 5.3 CVE-2019-12245 SilverStripe through 4.3.3 has incorrect access control for protected files uploaded via Upload::loadIntoFile(). An attacker may be able to guess a f… Silverstripe after 4.3.3 Fix from $1,6002019-09-25 HIGH 7.8 CVE-2019-13355 In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\ used by ccschedulersvc.ex… Anti Virus No fix yet Fix from $1,9502019-09-24 HIGH 7.8 CVE-2019-13356 In Total Defense Anti-virus 9.0.0.773, insecure access control for the directory %PROGRAMDATA%\TotalDefense\Consumer\ISS\9\bd\TDUpdate2\ used by AMRT… Anti Virus No fix yet Fix from $1,9502019-09-24 HIGH 8.8 CVE-2019-9008 An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime. Control For Beaglebone 3.5.13.0+ Fix from $1,9502019-09-17 MEDIUM 5.4 CVE-2019-15721 An issue was discovered in GitLab Community and Enterprise Edition 10.8 through 12.2.1. An internal endpoint unintentionally allowed group maintainer… GitLab 12.0.8 / 12.1.8+ Fix from $1,6002019-09-16 MEDIUM 6.7 CVE-2019-11166 Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially … Easy Streaming Wizard 2.1.0731+ Fix from $1,6002019-09-16 HIGH 7.5 CVE-2019-16187 Limesurvey before 3.17.14 uses an anti-CSRF cookie without the HttpOnly flag, which allows attackers to access a cookie value via a client-side scrip… Limesurvey 3.17.14+ Fix from $1,9502019-09-09 HIGH 7.8 CVE-2018-18630 A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker w… Horizon Cardiology Firmware after 12.2 Fix from $1,9502019-09-06 HIGH 7.8 CVE-2019-12645 A vulnerability in Cisco Jabber Client Framework (JCF) for Mac Software, installed as part of the Cisco Jabber for Mac client, could allow an authent… Jabber 12.6+ Fix from $1,9502019-09-05 HIGH 7.8 CVE-2019-15752 KEVEPSS 32% Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exe file in… Docker 2.1.0.1+ Fix from $1,9502019-08-28 HIGH 7.8 CVE-2019-15315 Valve Steam Client for Windows through 2019-08-16 allows privilege escalation (to NT AUTHORITY\SYSTEM) because local users can replace the current ve… Steam Client after 2019-08-16 Fix from $1,9502019-08-21 HIGH 7.0 CVE-2019-15316 Valve Steam Client for Windows through 2019-08-20 has weak folder permissions, leading to privilege escalation (to NT AUTHORITY\SYSTEM) via crafted u… Steam Client after 2019-08-20 Fix from $1,9502019-08-21 HIGH 7.8 CVE-2019-13069 extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The attacker must replace SilverS… Silvershield after 6.1.14.144 Fix from $1,9502019-08-17