Vulnerability index

Browse CVEs

1,504 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
HIGH 7.8 CVE-2017-7850 Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode. Nessus Mitigation only Fix from $1,9502017-04-19 HIGH 7.8 CVE-2017-7889 The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to… Linux Kernel 3.2.91 / 3.10.107+ Fix from $1,9502017-04-17 HIGH 8.8 CVE-2017-3006EPSS 11% Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creativ… Creative Cloud after 3.9.5.353 Fix from $1,9502017-04-12 MEDIUM 6.4 CVE-2017-0883 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the O… Nextcloud Server after 9.0.54 Fix from $1,6002017-04-05 MEDIUM 6.5 CVE-2017-6338 Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user… Interscan Web Security Virtual Appliance after 6.5 Fix from $1,6002017-04-05 MEDIUM 6.8 CVE-2017-7307 Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to o… Rios after 9.0.0b Fix from $1,6002017-04-04 HIGH 8.8 CVE-2017-5199 The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/c… Log And Event Manager after 6.3.1 Fix from $1,9502017-03-24 CRITICAL 9.8 CVE-2017-6950 SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a… Gui For Windows Mitigation only Fix from $2,3002017-03-23 HIGH 7.8 CVE-2017-7199 Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is run… Nessus Mitigation only Fix from $1,9502017-03-23 MEDIUM 5.3 CVE-2017-6356 Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows atta… Terminal Services Agent Mitigation only Fix from $1,6002017-03-20 HIGH 8.8 CVE-2017-2290 On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu… Mcollective Puppet Agent Mitigation only Fix from $1,9502017-03-03 HIGH 7.5 CVE-2017-6104EPSS 7% Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0. Zen Mobile App Native after 3.0 Fix from $1,9502017-03-02 HIGH 8.8 CVE-2017-0311 NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service … Gpu Driver Mitigation only Fix from $1,9502017-02-15 HIGH 7.5 CVE-2017-0317 All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extractio… Gpu Driver Mitigation only Fix from $1,9502017-02-15 MEDIUM 5.3 CVE-2017-0423 An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rat… Android Mitigation only Fix from $1,6002017-02-08 HIGH 7.5 CVE-2013-0885 Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interac… Chrome 25.0.1364.97 / 25.0.1364.99+ Fix from $1,9502013-02-23 HIGH 7.5 CVE-2013-0887 The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restric… Chrome 25.0.1364.97 / 25.0.1364.99+ Fix from $1,9502013-02-23 MEDIUM 6.5 CVE-2010-2116 The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privi… Email Gateway No fix yet Fix from $1,6002010-05-28 MEDIUM 6.5 CVE-2010-0488EPSS 29% Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas… Internet Explorer Patch available Fix from $1,6002010-03-31 MEDIUM 5.5 CVE-2009-3897 Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbi… Dovecot 1.2.8+ Fix from $1,6002009-11-24 HIGH 7.1 CVE-2009-3939 The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t… Linux Kernel after 2.6.31.6 Fix from $1,9502009-11-16 HIGH 7.1 CVE-2009-3611 common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, … Fedora Patch available Fix from $1,9502009-10-26 HIGH 7.8 CVE-2009-3482 TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%,… Antivirus 2.0.0.1291 / 2.8.0.2266+ Fix from $1,9502009-09-30 HIGH 7.8 CVE-2009-3489 Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) … Photoshop Elements No fix yet Fix from $1,9502009-09-30 HIGH 7.8 CVE-2009-3289 The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted lo… Glib No fix yet Fix from $1,9502009-09-22 MEDIUM 5.5 CVE-2009-1073 nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for … Nss Ldap 0.6.8+ Fix from $1,6002009-03-31 HIGH 7.8 CVE-2009-0115 The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server … Fedora after 11.0 Fix from $1,9502009-03-30 MEDIUM 5.5 CVE-2009-0141 XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local use… Mac Os X Mitigation only Fix from $1,6002009-02-13 HIGH 7.8 CVE-2008-0662 The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRem… Vpn 1 Secureclient Mitigation only Fix from $1,9502008-02-08 HIGH 8.8 CVE-2007-6033 Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers… Intouch Mitigation only Fix from $1,9502007-11-20