Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,724 CVEs tagged with CWE-732143 Critical, 849 High, 634 Medium, 98 Low, 0 Unrated.

CVE-2018-18435

Published Mar 21, 2019

KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15508

Published Mar 21, 2019

Five9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a connection on port 8083 to a device running th…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18254

Published Mar 15, 2019

An issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App Launcher (CAL) database, and potentially gain…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12223

Published Mar 14, 2019

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12217

Published Mar 14, 2019

Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-12209

Published Mar 14, 2019

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2018-12200

Published Mar 14, 2019

Insufficient access control in Intel(R) Capability Licensing Service before version 1.50.638.1 may allow an unprivileged user to potentially escalate privileges via local access.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20621

Published Mar 13, 2019

An issue was discovered in Microvirt MEmu 6.0.6. The MemuService.exe service binary is vulnerable to local privilege escalation through binary planting due to insecure permissions…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1618

Published Mar 11, 2019

A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to execute arbitrary co…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1601

Published Mar 8, 2019

A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file.…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2019-1600

Published Mar 7, 2019

A vulnerability in the file system permissions of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker to access sensitive information that is…

CVSS 4.4 · Medium

CVE-2018-20798

Published Mar 1, 2019

The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18495

Published Feb 28, 2019

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12396

Published Feb 28, 2019

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the Web…

CVSS 6.5 · Medium

CVE-2019-2001

Published Feb 28, 2019

The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7729

Published Feb 22, 2019

An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving vid…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-0111

Published Feb 18, 2019

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0108

Published Feb 18, 2019

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local acces…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13374

Published Jan 22, 2019

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials c…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
53.9
KEV listed
Vendor/product tagsBeta · best-effort
Showing 1,351-1,375 of 1,724 CVEsPage 55 of 69