Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,724 CVEs tagged with CWE-732143 Critical, 849 High, 634 Medium, 98 Low, 0 Unrated.

CVE-2018-5413

Published Jan 10, 2019

Imperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in privilege escalation.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0449

Published Jan 10, 2019

A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16087

Published Jan 9, 2019

Lack of proper state tracking in Permissions in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0588

Published Jan 8, 2019

An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-20131

Published Jan 3, 2019

The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20567

Published Dec 28, 2018

An issue was discovered in DouCo DouPHP 1.5 20181221. \install\index.php allows a reload of the product in opportunistic circumstances in which install.lock cannot be read.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-20420

Published Dec 24, 2018

In webERP 4.15, Z_CreateCompanyTemplateFile.php has Incorrect Access Control, leading to the overwrite of an existing .sql file on the target web site by creating a template and t…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18332

Published Dec 21, 2018

A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18331

Published Dec 21, 2018

A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other e…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11964

Published Dec 20, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Exposing the hashed content in /etc/passwd may lead to security issue.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6978

Published Dec 18, 2018

vRealize Operations (7.x before 7.0.0.11287810, 6.7.x before 6.7.0.11286837 and 6.6.x before 6.6.1.11286876) contains a local privilege escalation vulnerability due to improper pe…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-3705

Published Dec 14, 2018

Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authenticated users to potentially enable a denial of service via…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18097

Published Dec 14, 2018

Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18093

Published Dec 14, 2018

Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20145

Published Dec 13, 2018

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specifie…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6755

Published Dec 6, 2018

Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafte…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14703

Published Dec 3, 2018

Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root p…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,376-1,400 of 1,724 CVEsPage 56 of 69