Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,704 CVEs tagged with CWE-732142 Critical, 839 High, 625 Medium, 96 Low, 2 Unrated.

CVE-2018-14043

Published Jul 13, 2018

mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9604

Published Jul 11, 2018

It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstrea…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13791

Published Jul 9, 2018

The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCapt…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-7471

Published Jul 9, 2018

Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-13122

Published Jul 3, 2018

onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=ed…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-0913

Published Jul 3, 2018

Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a do…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11642

Published Jul 3, 2018

Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-10856

Published Jul 3, 2018

It has been discovered that podman before version 0.6.1 does not drop capabilities when executing a container as a non-root user. This results in unnecessary privileges being gran…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10843

Published Jul 2, 2018

source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13025

Published Jun 29, 2018

protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000547

Published Jun 26, 2018

coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no pe…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000511

Published Jun 26, 2018

WP ULike version 2.8.1, 3.1 contains a Incorrect Access Control vulnerability in AJAX that can result in allows anybody to delete any row in certain tables. This attack appear to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000510

Published Jun 26, 2018

WP Image Zoom version 1.23 contains a Incorrect Access Control vulnerability in AJAX settings that can result in allows anybody to cause denial of service. This attack appear to b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-12642

Published Jun 22, 2018

Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12615

Published Jun 21, 2018

An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up t…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11116

Published Jun 19, 2018

OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus ac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12028

Published Jun 17, 2018

An Incorrect Access Control vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 allows a Passenger-managed malicious application, upon spawning a child process, t…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,476-1,500 of 1,704 CVEsPage 60 of 69