Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2017-7850
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions when running in Agent Mode.
Nessus
Mitigation only
HIGH 7.8
CVE-2017-7889
The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism, which allows local users to…
Linux Kernel
3.2.91 / 3.10.107+
HIGH 8.8
CVE-2017-3006EPSS 11%
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creativ…
Creative Cloud
after 3.9.5.353
MEDIUM 6.4
CVE-2017-0883
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the O…
Nextcloud Server
after 9.0.54
MEDIUM 6.5
CVE-2017-6338
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user…
Interscan Web Security Virtual Appliance
after 6.5
MEDIUM 6.8
CVE-2017-7307
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to o…
Rios
after 9.0.0b
HIGH 8.8
CVE-2017-5199
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/c…
Log And Event Manager
after 6.3.1
CRITICAL 9.8
CVE-2017-6950
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, a…
Gui For Windows
Mitigation only
HIGH 7.8
CVE-2017-7199
Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privileges when the software is run…
Nessus
Mitigation only
MEDIUM 5.3
CVE-2017-6356
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows atta…
Terminal Services Agent
Mitigation only
HIGH 8.8
CVE-2017-2290
On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be execu…
Mcollective Puppet Agent
Mitigation only
HIGH 7.5
CVE-2017-6104EPSS 7%
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
Zen Mobile App Native
after 3.0
HIGH 8.8
CVE-2017-0311
NVIDIA GPU Display Driver R378 contains a vulnerability in the kernel mode layer handler where improper access control may lead to denial of service …
Gpu Driver
Mitigation only
HIGH 7.5
CVE-2017-0317
All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permissions on the package extractio…
Gpu Driver
Mitigation only
MEDIUM 5.3
CVE-2017-0423
An elevation of privilege vulnerability in Bluetooth could enable a proximate attacker to manage access to documents on the device. This issue is rat…
Android
Mitigation only
HIGH 7.5
CVE-2013-0885
Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interac…
Chrome
25.0.1364.97 / 25.0.1364.99+
HIGH 7.5
CVE-2013-0887
The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restric…
Chrome
25.0.1364.97 / 25.0.1364.99+
MEDIUM 6.5
CVE-2010-2116
The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privi…
Email Gateway
No fix yet
MEDIUM 6.5
CVE-2010-0488EPSS 29%
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypas…
Internet Explorer
Patch available
MEDIUM 5.5
CVE-2009-3897
Dovecot 1.2.x before 1.2.8 sets 0777 permissions during creation of certain directories at installation time, which allows local users to access arbi…
Dovecot
1.2.8+
HIGH 7.1
CVE-2009-3939
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t…
Linux Kernel
after 2.6.31.6
HIGH 7.1
CVE-2009-3611
common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, …
Fedora
Patch available
HIGH 7.8
CVE-2009-3482
TrustPort Antivirus before 2.8.0.2266 and PC Security before 2.0.0.1291 use weak permissions (Everyone: Full Control) for files under %PROGRAMFILES%,…
Antivirus
2.0.0.1291 / 2.8.0.2266+
HIGH 7.8
CVE-2009-3489
Adobe Photoshop Elements 8.0 installs the Adobe Active File Monitor V8 service with an insecure security descriptor, which allows local users to (1) …
Photoshop Elements
No fix yet
HIGH 7.8
CVE-2009-3289
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted lo…
Glib
No fix yet
MEDIUM 5.5
CVE-2009-1073
nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for …
Nss Ldap
0.6.8+
HIGH 7.8
CVE-2009-0115
The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server …
Fedora
after 11.0
MEDIUM 5.5
CVE-2009-0141
XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local use…
Mac Os X
Mitigation only
HIGH 7.8
CVE-2008-0662
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRem…
Vpn 1 Secureclient
Mitigation only
HIGH 8.8
CVE-2007-6033
Invensys Wonderware InTouch 8.0 creates a NetDDE share with insecure permissions (Everyone/Full Control), which allows remote authenticated attackers…
Intouch
Mitigation only