Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,711 CVEs tagged with CWE-732143 Critical, 842 High, 629 Medium, 97 Low, 0 Unrated.

CVE-2018-3697

Published Nov 14, 2018

Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of privilege via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-2490

Published Nov 13, 2018

The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must up…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2489

Published Nov 13, 2018

Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.11.5 in Google Play store addr…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2121

Published Oct 31, 2018

A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged use…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18654

Published Oct 26, 2018

Crossroads 2.81 does not properly handle the /tmp directory during a build of xr. A local attacker can first create a world-writable subdirectory in a certain location under the /…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11792

Published Oct 24, 2018

In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a parti…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-18348

Published Oct 19, 2018

Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local users to gain privileges by leveraging access to that non-…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11080

Published Oct 18, 2018

Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains Improper File Permission Vulnerabilities. The application contains multiple configuration files with world-…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13399

Published Oct 16, 2018

The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installati…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-17892

Published Oct 12, 2018

NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, whi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1724

Published Oct 11, 2018

IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 14…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17775

Published Oct 8, 2018

Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,401-1,425 of 1,711 CVEsPage 57 of 69