Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Permission AssignmentCWE-732 × clear
Dpkg HIGH 8.2
CVE-2025-6297

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which i…

Fix: 1.22.21+
Fix from $1,950 2025-07-01
Debian Linux MEDIUM 5.3
CVE-2023-45364

An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision exis…

Fix: 1.39.5+
Fix from $1,600 2023-10-09
Debian Linux MEDIUM 6.5
CVE-2022-46338

g810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable and writabl…

Patch available
Fix from $1,600 2022-11-30
Logcheck CRITICAL 9.8
CVE-2017-20148

In the ebuild package through logcheck-1.3.23.ebuild for Logcheck on Gentoo, it is possible to achieve root privilege escalation from the logcheck us…

Fix: after 1.3.23
Fix from $2,300 2022-09-20
Courier Authlib HIGH 7.5
CVE-2021-28374

The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissio…

Fix: 0.71.1-2+
Fix from $1,950 2021-03-15
Debian Linux HIGH 7.0
CVE-2020-28169

The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account…

Fix: 2020-12-18+
Fix from $1,950 2020-12-24
Debian Linux MEDIUM 5.5
CVE-2020-17490

The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.

Fix: 2015.8.10 / 2015.8.13+
Fix from $1,600 2020-11-06
Debian Linux MEDIUM 5.5
CVE-2020-15250

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like syste…

Fix: 3.1.1 / 4.13.1+
Fix from $1,600 2020-10-12
Debian Lan Config HIGH 7.8
CVE-2019-3467

Debian-edu-config all versions < 2.11.10, a set of configuration files used for Debian Edu, and debian-lan-config < 0.26, configured too permissive A…

Fix: 0.26 / 2.11.10+
Fix from $1,950 2019-12-23
Debian Linux MEDIUM 5.5
CVE-2013-0326

OpenStack nova base images permissions are world readable

Mitigation only
Fix from $1,600 2019-12-05
Debian Linux MEDIUM 5.3
CVE-2011-2515

PackageKit 0.6.17 allows installation of unsigned RPM packages as though they were signed which may allow installation of non-trusted packages and ex…

Mitigation only
Fix from $1,600 2019-11-27
Debian Linux HIGH 7.5
CVE-2007-5743

viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.

No fix yet
Fix from $1,950 2019-11-07
Debian Linux HIGH 8.8
CVE-2019-18422

An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous…

Fix: after 4.12.1
Fix from $1,950 2019-10-31
Crossroads HIGH 7.8
CVE-2018-18654

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in …

Mitigation only
Fix from $1,950 2018-10-26
Debian Linux CRITICAL 9.1
CVE-2018-1000132

Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data…

Fix: 4.5.1+
Fix from $2,300 2018-03-14
Debian Linux MEDIUM 5.3
CVE-2017-15906

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers …

Fix: 7.6+
Fix from $1,600 2017-10-26
Debian Linux HIGH 7.8
CVE-2017-9780

In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate permissions, for example set…

Fix: after 0.8.6
Fix from $1,950 2017-06-21
Debian Linux HIGH 8.8
CVE-2017-9462EPSS 22%

In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary cod…

Fix: 4.1.3+
Fix from $1,950 2017-06-06
Debian Linux HIGH 7.8
CVE-2017-7493

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable to an improper access control…

Fix: after 2.9.1
Fix from $1,950 2017-05-17
Nss Ldap MEDIUM 5.5
CVE-2009-1073

nss-ldapd before 0.6.8 uses world-readable permissions for the /etc/nss-ldapd.conf file, which allows local users to obtain a cleartext password for …

Fix: 0.6.8+
Fix from $1,600 2009-03-31