Vulnerabilities (CVE)

Filtered by CWE-276
Total 1230 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18669 1 Google 1 Android 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).
CVE-2017-18668 1 Google 1 Android 2024-11-21 5.0 MEDIUM 7.5 HIGH
An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).
CVE-2017-16128 1 Npm-script-demo Project 1 Npm-script-demo 2024-11-21 10.0 HIGH 9.8 CRITICAL
The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
CVE-2017-16127 1 Pandora-doomsday Project 1 Pandora-doomsday 2024-11-21 10.0 HIGH 9.8 CRITICAL
The module pandora-doomsday infects other modules. It's since been unpublished from the registry.
CVE-2017-0369 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
CVE-2015-9477 1 Vernissage Project 1 Vernissage 2024-11-21 6.5 MEDIUM 8.8 HIGH
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
CVE-2015-9476 1 Teardrop Project 1 Teardrop 2024-11-21 6.5 MEDIUM 8.8 HIGH
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
CVE-2015-9475 1 Pont Project 1 Pont 2024-11-21 6.5 MEDIUM 8.8 HIGH
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
CVE-2015-9474 1 Simpolio Project 1 Simpolio 2024-11-21 6.5 MEDIUM 8.8 HIGH
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
CVE-2014-7303 1 Hp 1 Sgi Tempo 2024-11-21 7.2 HIGH 7.8 HIGH
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.
CVE-2014-7302 1 Hp 1 Sgi Tempo 2024-11-21 7.2 HIGH 7.8 HIGH
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
CVE-2014-7301 1 Hp 1 Sgi Tempo 2024-11-21 4.6 MEDIUM 6.6 MEDIUM
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
CVE-2014-2723 1 Fortinet 8 Fortibalancer 1000, Fortibalancer 1000 Firmware, Fortibalancer 2000 and 5 more 2024-11-21 9.0 HIGH 8.8 HIGH
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.
CVE-2014-2722 1 Fortinet 8 Fortibalancer 1000, Fortibalancer 1000 Firmware, Fortibalancer 2000 and 5 more 2024-11-21 9.0 HIGH 8.8 HIGH
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.
CVE-2014-2721 1 Fortinet 8 Fortibalancer 1000, Fortibalancer 1000 Firmware, Fortibalancer 2000 and 5 more 2024-11-21 9.0 HIGH 8.8 HIGH
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is not the result of an underlying SSH defect.
CVE-2013-4859 1 Insteon 2 Hub, Hub Firmware 2024-11-21 9.3 HIGH 8.1 HIGH
INSTEON Hub 2242-222 lacks Web and API authentication
CVE-2013-4764 1 Samsung 4 Galaxy S3, Galaxy S3 Firmware, Galaxy S4 and 1 more 2024-11-21 2.1 LOW 4.3 MEDIUM
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
CVE-2013-4763 1 Samsung 4 Galaxy S3, Galaxy S3 Firmware, Galaxy S4 and 1 more 2024-11-21 2.1 LOW 4.6 MEDIUM
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
CVE-2013-4281 1 Redhat 1 Openshift 2024-11-21 N/A 5.5 MEDIUM
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
CVE-2013-1425 2 Debian, Ldap Git Backup Project 2 Debian Linux, Ldap Git Backup 2024-11-21 2.1 LOW 5.5 MEDIUM
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.