Total
1191 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2019-17043 | 1 Bmc | 1 Patrol Agent | 2024-11-21 | 7.8 High |
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared library .so file that will be loaded during execution. | ||||
CVE-2019-16919 | 2 Linuxfoundation, Vmware | 3 Harbor, Cloud Foundation, Harbor Container Registry | 2024-11-21 | 7.5 High |
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access or control for. The Harbor API did not enforce the proper project permissions and project scope on the API request to create a new robot account. | ||||
CVE-2019-16913 | 1 Pcprotect | 1 Antivirus | 2024-11-21 | 7.8 High |
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the program installs a service called SecurityService that runs as LocalSystem. This allows any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a Trojan horse. | ||||
CVE-2019-16716 | 1 Open-xchange | 1 Open-xchange Appsuite | 2024-11-21 | 6.6 Medium |
OX App Suite through 7.10.2 has Incorrect Access Control. | ||||
CVE-2019-16559 | 1 Jenkins | 1 Websphere Deployer | 2024-11-21 | 5.4 Medium |
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins master file system. | ||||
CVE-2019-16554 | 1 Jenkins | 1 Build Failure Analyzer | 2024-11-21 | 4.3 Medium |
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression. | ||||
CVE-2019-16552 | 1 Jenkins | 1 Gerrit Trigger | 2024-11-21 | 5.4 Medium |
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials, or determine the existence of a file with a given path on the Jenkins master. | ||||
CVE-2019-16355 | 1 Beego | 1 Beego | 2024-11-21 | 5.5 Medium |
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files. | ||||
CVE-2019-16186 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 7.2 High |
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions. | ||||
CVE-2019-16185 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 7.2 High |
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions. | ||||
CVE-2019-16183 | 1 Limesurvey | 1 Limesurvey | 2024-11-21 | 2.7 Low |
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions. | ||||
CVE-2019-16106 | 1 Humanica | 1 Humatrix | 2024-11-21 | 7.5 High |
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | ||||
CVE-2019-16061 | 1 Netsas | 1 Enigma Network Management Solution | 2024-11-21 | 8.8 High |
A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g., .htpasswd) and create/modify/delete content (e.g., under /var/www/html/docs) within the operating system. | ||||
CVE-2019-15793 | 2 Canonical, Linux | 2 Ubuntu Linux, Linux Kernel | 2024-11-21 | 6.5 Medium |
In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for the lower filesystem. This resulted in using ids other than the intended ones in the lower fs, which likely did not map into the shifts s_user_ns. A local attacker could use this to possibly bypass discretionary access control permissions. | ||||
CVE-2019-15716 | 1 Wtfutil | 1 Wtf | 2024-11-21 | N/A |
WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults. | ||||
CVE-2019-15011 | 1 Atlassian | 1 Application Links | 2024-11-21 | 4.3 Medium |
The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0 before 6.0.5 disclosed application link information to non-admin users via a missing permissions check. | ||||
CVE-2019-14925 | 2 Inea, Mitsubishielectric | 4 Me-rtu, Me-rtu Firmware, Smartrtu and 1 more | 2024-11-21 | 6.5 Medium |
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. | ||||
CVE-2019-14861 | 5 Canonical, Debian, Fedoraproject and 2 more | 5 Ubuntu Linux, Debian Linux, Fedora and 2 more | 2024-11-21 | 5.3 Medium |
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permissions on the DNS partition allow creation of new records by authenticated users. This is used for example to allow machines to self-register in DNS. If a DNS record was created that case-insensitively matched the name of the zone, the ldb_qsort() and dns_name_compare() routines could be confused into reading memory prior to the list of DNS entries when responding to DnssrvEnumRecords() or DnssrvEnumRecords2() and so following invalid memory as a pointer. | ||||
CVE-2019-14737 | 1 Ubisoft | 1 Uplay | 2024-11-21 | 7.8 High |
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. | ||||
CVE-2019-14718 | 1 Verifone | 2 Mx900, Mx900 Firmware | 2024-11-21 | 6.7 Medium |
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 have Insecure Permissions, with resultant svc_netcontrol arbitrary command injection and privilege escalation. |