Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,704 CVEs tagged with CWE-732142 Critical, 839 High, 625 Medium, 96 Low, 2 Unrated.

CVE-2018-17776

Published Sep 28, 2018

PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a T…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16588

Published Sep 26, 2018

Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and thro…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14327

Published Sep 26, 2018

The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Contr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8848

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14825

Published Sep 24, 2018

On Honeywell Mobile Computers (CT60 running Android OS 7.1, CN80 running Android OS 7.1, CT40 running Android OS 7.1, CK75 running Android OS 6.0, CN75 running Android OS 6.0, CN7…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2018-16958

Published Sep 18, 2018

An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The ASP.NET_SessionID primary session cookie, when Internet Information Services (IIS) with ASP.NET is used,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-17037

Published Sep 14, 2018

user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12168

Published Sep 12, 2018

Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potentially execute code as administr…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12162

Published Sep 12, 2018

Directory permissions in the Intel OpenVINO Toolkit for Windows before version 2018.1.265 may allow an authenticated user to potentially execute code using default directory permi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12148

Published Sep 12, 2018

Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via loca…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15502

Published Sep 12, 2018

Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13412

Published Sep 12, 2018

An issue was discovered in the Self Service Portal in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to es…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13411

Published Sep 12, 2018

An issue was discovered in Zoho ManageEngine Desktop Central before 10.0.282. A clickable company logo in a window running as SYSTEM can be abused to escalate privileges. In cloud…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11078

Published Sep 11, 2018

Dell EMC VPlex GeoSynchrony, versions prior to 6.1, contains an Insecure File Permissions vulnerability. A remote authenticated malicious user could read from VPN configuration fi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16715

Published Sep 8, 2018

An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write acces…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16703

Published Sep 7, 2018

A vulnerability in the Gleez CMS 1.2.0 login page could allow an unauthenticated, remote attacker to perform multiple user enumerations, which can further help an attacker to perf…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000660

Published Sep 6, 2018

TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permissions vulnerability in Functi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16145

Published Sep 5, 2018

The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user,…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-15681

Published Sep 5, 2018

An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1,426-1,450 of 1,704 CVEsPage 58 of 69