Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
MEDIUM 6.5 CVE-2017-1000221 In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the … Opencast after 2.2.3 Fix from $1,6002017-11-17 HIGH 7.5 CVE-2017-1000125 Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell. Codiad No fix yet Fix from $1,9502017-11-17 HIGH 7.8 CVE-2017-0830 An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8… Android Patch available Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-0831 An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Android ID: A-37442941. Android Patch available Fix from $1,9502017-11-16 HIGH 7.5 CVE-2017-0845 A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1… Android Patch available Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-16834 PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depends on these files, which allow… Pnp4nagios after 0.6.26 Fix from $1,9502017-11-16 HIGH 7.8 CVE-2017-15288 The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-… Scala 2.10.7 / 2.11.12+ Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-3166 In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access permissions that make it worl… Hadoop Mitigation only Fix from $1,9502017-11-13 MEDIUM 5.3 CVE-2017-16754 Bolt before 3.3.6 does not properly restrict access to _profiler routes, related to EventListener/ProfilerListener.php and Provider/EventListenerServ… Bolt after 3.3.5 Fix from $1,6002017-11-10 HIGH 7.8 CVE-2017-16757 Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.… Vpn No fix yet Fix from $1,9502017-11-09 HIGH 7.8 CVE-2017-16659 The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to in… Anti Spam Smtp Proxy after 1.9.8.13030 Fix from $1,9502017-11-08 CRITICAL 9.8 CVE-2017-16638 The Gentoo net-misc/vde package before version 2.3.2-r4 may allow members of the "qemu" group to gain root privileges by creating a hard link in a di… Vde 2.3.2+ Fix from $2,3002017-11-06 CRITICAL 9.8 CVE-2017-1000153 Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset li… Mahara Patch available Fix from $2,3002017-11-03 HIGH 8.1 CVE-2017-1000134 Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are vulnerable because group members can lose access to … Mahara Patch available Fix from $1,9502017-11-03 HIGH 7.8 CVE-2017-15945 The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and dev-db/mariadb-galera packages … MariaDB 5.6.36 / 10.0.30+ Fix from $1,9502017-10-27 MEDIUM 5.3 CVE-2017-15906 The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers … Debian Linux 7.6+ Fix from $1,6002017-10-26 MEDIUM 5.3 CVE-2017-7146 An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Security" component. It allows attackers to tra… Iphone Os after 10.3.3 Fix from $1,6002017-10-23 MEDIUM 6.5 CVE-2017-15611 In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserInvite) can invite users to te… Octopus Deploy after 3.17.6 Fix from $1,6002017-10-19 HIGH 8.8 CVE-2017-9514 Bamboo before 6.0.5, 6.1.x before 6.1.4, and 6.2.x before 6.2.1 had a REST endpoint that parsed a YAML file and did not sufficiently restrict which c… Bamboo Mitigation only Fix from $1,9502017-10-12 MEDIUM 6.5 CVE-2017-1000095 The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, S… Script Security Mitigation only Fix from $1,6002017-10-05 HIGH 8.8 CVE-2017-1000096 Arbitrary code execution due to incomplete sandbox protection: Constructors, instance variable initializers, and instance initializers in Pipeline sc… Pipeline\ after 2.36 Fix from $1,9502017-10-05 MEDIUM 6.5 CVE-2017-9792 In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any other Kudu table data by alt… Impala Mitigation only Fix from $1,6002017-10-04 HIGH 7.8 CVE-2017-9958 An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which an improper handl… U.motion Builder after 1.2.1 Fix from $1,9502017-09-26 HIGH 7.8 CVE-2017-14730 The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls for user-writable directory tre… Logstash Patch available Fix from $1,9502017-09-25 HIGH 7.8 CVE-2017-13779 GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offlin… India Goods And Services Tax Network Offline Utility Tool after 1.1 Fix from $1,9502017-09-14 MEDIUM 5.5 CVE-2017-7560 It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill selected processes. Rhnsd Mitigation only Fix from $1,6002017-09-13 HIGH 8.8 CVE-2017-0784 A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android … Android Patch available Fix from $1,9502017-09-08 HIGH 7.8 CVE-2017-0752 A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.… Android Patch available Fix from $1,9502017-09-08 HIGH 7.8 CVE-2017-12713 An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Multiple files … Webaccess after 8.2 Fix from $1,9502017-08-30 CRITICAL 9.8 CVE-2017-12816 In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, which might be used by a malwa… Internet Security Mitigation only Fix from $2,3002017-08-25