Skip to main content

CWE archive

CWE-552 CVEs

Programmatic archive

483 CVEs tagged with CWE-55244 Critical, 201 High, 225 Medium, 13 Low, 0 Unrated.

CVE-2019-13404

Published Jul 8, 2019

The MSI installer for Python through 2.7.16 on Windows defaults to the C:\Python27 directory, which makes it easier for local users to deploy Trojan horse code. (This also affects…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3569

Published Jun 26, 2019

HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintended direct access to the application, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12375

Published Jun 3, 2019

Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosure and arbitrary code execution.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-9587

Published Feb 11, 2019

In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2, Android-8.0, Android-8.1 and Android-9, there is possible unauthorized access to f…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6922

Published Jan 22, 2019

In Drupal core 8.x prior to 8.3.4 and Drupal core 7.x prior to 7.56; Private files that have been uploaded by an anonymous user but not permanently attached to content on the site…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2017-2621

Published Jul 27, 2018

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A ma…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2622

Published Jul 27, 2018

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-5112

Published Jun 11, 2018

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all in…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-1602

Published Mar 23, 2018

IBM RSA DM (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) could allow an authenticated user to access settings that they should not be able to using a specially cra…

CVSS 4.3 · Medium

CVE-2018-0106

Published Jan 18, 2018

A vulnerability in the ConfD server of the Cisco Elastic Services Controller (ESC) could allow an unauthenticated, local attacker to access sensitive information on a targeted sys…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2017-12079

Published Dec 4, 2017

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-16651

Published Nov 9, 2017

Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary files on the host's filesystem, including configuration files,…

CVSS 7.8 · High
Buzz score
25.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2017-7079

Published Oct 23, 2017

An issue was discovered in certain Apple products. iTunes before 12.7 is affected. The issue involves the "Data Sync" component. It allows attackers to access iOS backups (written…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-2551

Published Sep 28, 2017

Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6774

Published Aug 17, 2017

A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 451-475 of 483 CVEsPage 19 of 20