Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 8.4 CVE-2017-11652 Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the CrashReporter directory, which allows local users to gain privileges via a Troja… Synapse after 2.20.15.1104 Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-11653 Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain privileges via a Trojan hors… Synapse after 2.20.15.1104 Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-8665 The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin.iOS Elevation Of Privilege V… Xamarin.ios after 10.11 Fix from $1,9502017-08-15 HIGH 7.8 CVE-2017-11156 Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows re… Download Station Mitigation only Fix from $1,9502017-08-14 MEDIUM 6.5 CVE-2017-11437 GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to us… GitLab Mitigation only Fix from $1,6002017-08-02 CRITICAL 9.8 CVE-2017-9479 The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to execute arbitr… Dpc3939 Firmware No fix yet Fix from $2,3002017-07-31 CRITICAL 9.8 CVE-2017-9482 The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to obtain root ac… Dpc3939 Firmware No fix yet Fix from $2,3002017-07-31 MEDIUM 5.3 CVE-2017-9494 The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspecto… Mx011anm Firmware Mitigation only Fix from $1,6002017-07-31 HIGH 8.8 CVE-2017-11422 Statamic framework before 2.6.0 does not correctly check a session's permissions when the methods from a user's class are called. Problematic methods… Statamic 2.6.0+ Fix from $1,9502017-07-24 HIGH 8.8 CVE-2017-1000022 LogicalDoc Community Edition 7.5.3 and prior contain an Incorrect access control which could leave to privilege escalation. Logicaldoc after 7.5.3 Fix from $1,9502017-07-17 HIGH 7.8 CVE-2017-0703 A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Andr… Android Mitigation only Fix from $1,9502017-07-06 CRITICAL 9.8 CVE-2017-9615 Password exposure in Cognito Software Moneyworks 8.0.3 and earlier allows attackers to gain administrator access to all data, because verbose logging… Moneyworks after 8.0.3 Fix from $2,3002017-06-26 HIGH 7.8 CVE-2017-9780 In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example set… Debian Linux after 0.8.6 Fix from $1,9502017-06-21 MEDIUM 5.9 CVE-2017-8449 X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl… X Pack after 5.2.2 Fix from $1,6002017-06-16 HIGH 7.5 CVE-2017-8450 X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an… X Pack Mitigation only Fix from $1,9502017-06-16 CRITICAL 9.8 CVE-2017-9602 KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component. An unauthe… Kbvault Mysql No fix yet Fix from $2,3002017-06-16 HIGH 7.3 CVE-2017-9606 Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the up… Vipnet Client after 4.3.1 Fix from $1,9502017-06-15 HIGH 8.1 CVE-2017-7563 In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mecha… Trusted Firmware A after 1.3 Fix from $1,9502017-06-07 HIGH 8.8 CVE-2017-9462EPSS 22% In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary cod… Debian Linux 4.1.3+ Fix from $1,9502017-06-06 CRITICAL 9.1 CVE-2017-7337 An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or e… Fortiportal after 4.0.0 Fix from $2,3002017-05-27 HIGH 7.5 CVE-2017-9136 An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsani… Backhaul Radios after 2.2.1 Fix from $1,9502017-05-21 HIGH 7.8 CVE-2017-7493 Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control… Debian Linux after 2.9.1 Fix from $1,9502017-05-17 HIGH 7.8 CVE-2017-0593 An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This… Android Patch available Fix from $1,9502017-05-12 MEDIUM 5.5 CVE-2017-0601 An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept harmful files shared via blueto… Android Patch available Fix from $1,6002017-05-12 HIGH 7.8 CVE-2017-0352 All versions of the NVIDIA GPU Display Driver contain a vulnerability in the GPU firmware where incorrect access control may allow CPU access sensiti… Gpu Driver Mitigation only Fix from $1,9502017-05-09 CRITICAL 9.8 CVE-2017-8856 In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution using the … Netbackup after 8.0 Fix from $2,3002017-05-09 CRITICAL 9.8 CVE-2017-8857EPSS 6% In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote command executi… Netbackup after 8.0 Fix from $2,3002017-05-09 CRITICAL 9.8 CVE-2017-8858 In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated privileged remote file write using the 'bprd' … Netbackup after 8.0 Fix from $2,3002017-05-09 MEDIUM 5.5 CVE-2017-8391 The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted password into a readable local file … Client Automation Mitigation only Fix from $1,6002017-05-06 MEDIUM 5.5 CVE-2017-7849 Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode. Nessus Mitigation only Fix from $1,6002017-04-19