Vulnerability index

Browse CVEs

1,503 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
CRITICAL 9.8 CVE-2019-7958 Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exploitation could lea… Creative Cloud after 4.6.1 Fix from $2,3002019-08-16 MEDIUM 5.5 CVE-2019-15119 lib/install/install.go in cnlh nps through 0.23.2 uses 0777 permissions for /usr/local/bin/nps and/or /usr/bin/nps, leading to a file overwrite by a … Nps after 0.23.2 Fix from $1,6002019-08-16 HIGH 7.8 CVE-2019-15084 Realtek Waves MaxxAudio driver 1.6.2.0, as used on Dell laptops, installs with incorrect file permissions. As a result, a local attacker can escalate… Waves Maxx Audio No fix yet Fix from $1,9502019-08-16 MEDIUM 6.5 CVE-2018-12357 Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions. Cloudvision Portal after 2018.1.1 Fix from $1,6002019-08-15 HIGH 8.8 CVE-2019-0341 The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the a… Enable Now Mitigation only Fix from $1,9502019-08-14 HIGH 7.8 CVE-2019-12808 ALTOOLS update service 18.1 and earlier versions contains a local privilege escalation vulnerability due to insecure permission. An attacker can over… Altools after 18.1 Fix from $1,9502019-08-13 HIGH 7.8 CVE-2019-14969 Netwrix Auditor before 9.8 has insecure permissions on %PROGRAMDATA%\Netwrix Auditor\Logs\ActiveDirectory\ and sub-folders. In addition, the service … Auditor 9.8+ Fix from $1,9502019-08-12 HIGH 7.8 CVE-2019-14935 3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control a… 3cx No fix yet Fix from $1,9502019-08-12 HIGH 7.3 CVE-2019-1944 Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to… Adaptive Security Appliance Software 9.4.4.37+ Fix from $1,9502019-08-07 MEDIUM 6.6 CVE-2019-14743 In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which al… Steam Client after 2019-08-07 Fix from $1,6002019-08-07 HIGH 7.5 CVE-2019-11270 Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can by… Application Service 2.3.15 / 2.3.22+ Fix from $1,9502019-08-05 MEDIUM 5.4 CVE-2018-20905 cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). Cpanel 62.0.47 / 68.0.39+ Fix from $1,6002019-08-01 MEDIUM 5.5 CVE-2018-20908 cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). Cpanel 62.0.47 / 68.0.39+ Fix from $1,6002019-08-01 HIGH 7.1 CVE-2018-20909 cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). Cpanel 62.0.42 / 68.0.33+ Fix from $1,9502019-08-01 CRITICAL 9.8 CVE-2018-20871 In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) oc… Grid Engine Mitigation only Fix from $2,3002019-07-30 HIGH 8.1 CVE-2018-2024 IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unint… Qradar Security Information And Event Manager Patch available Fix from $1,9502019-07-22 CRITICAL 9.8 CVE-2019-1010101 Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions. The impact is: arbitrary code execution with escalation of privilege. The… Rufus after 3.0 Fix from $2,3002019-07-19 MEDIUM 5.5 CVE-2019-5222 There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R… Honor Magic 2 Firmware Mitigation only Fix from $1,6002019-07-17 HIGH 7.3 CVE-2019-12876 Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalatio… Manageengine Admanager Plus No fix yet Fix from $1,9502019-07-17 CRITICAL 9.8 CVE-2019-1010009 DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions. The impact is: Remote Execution, Credential Leaks. The component is: IoT … Dglux Server Mitigation only Fix from $2,3002019-07-15 HIGH 7.8 CVE-2019-12577 A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run … Private Internet Access Vpn Client No fix yet Fix from $1,9502019-07-11 MEDIUM 5.5 CVE-2019-13142 The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located … Surround Mitigation only Fix from $1,6002019-07-09 HIGH 7.3 CVE-2019-13208 WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to … Waves Maxx Audio No fix yet Fix from $1,9502019-07-03 MEDIUM 6.5 CVE-2018-14861 Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of … Odoo Patch available Fix from $1,6002019-07-03 MEDIUM 6.5 CVE-2018-14862 Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated i… Odoo Patch available Fix from $1,6002019-07-03 CRITICAL 9.1 CVE-2018-14916EPSS 17% LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. Lgate 902 Firmware 6.4.2+ Fix from $2,3002019-06-28 HIGH 7.5 CVE-2019-13012 The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL,… Glib 2.59.1+ Fix from $1,9502019-06-28 HIGH 7.8 CVE-2019-2023 In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could al… Android Mitigation only Fix from $1,9502019-06-19 HIGH 7.8 CVE-2019-12133 Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory a… Manageengine Analytics Plus Mitigation only Fix from $1,9502019-06-18 HIGH 7.8 CVE-2018-19446 A File Write can occur for specially crafted PDF files in Foxit Reader SDK (ActiveX) Professional 5.4.0.1031 when the JavaScript API Doc.createDataOb… Foxit Pdf Sdk Activex after 5.5.0 Fix from $1,9502019-06-17