Total
1465 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-13896 | 1 Qualcomm | 72 Mdm9206, Mdm9206 Firmware, Mdm9607 and 69 more | 2019-07-25 | 7.2 HIGH | 7.8 HIGH |
XBL_SEC image authentication and other crypto related validations are accessible to a compromised OEM XBL Loader due to missing lock at XBL_SEC stage.. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in MDM9206, MDM9607, MDM9650, MDM9655, MSM8996AU, QCS404, QCS605, Qualcomm 215, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM439, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130 | |||||
CVE-2018-19588 | 1 Alarm | 2 Adc-v522ir, Adc-v522ir Firmware | 2019-07-18 | 9.0 HIGH | 7.2 HIGH |
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control. | |||||
CVE-2018-11744 | 1 Cloudera | 1 Cloudera Manager | 2019-07-18 | 6.8 MEDIUM | 8.1 HIGH |
Cloudera Manager through 5.15 has Incorrect Access Control. | |||||
CVE-2018-14833 | 1 Intuit | 1 Lacerte | 2019-07-16 | 4.3 MEDIUM | 5.9 MEDIUM |
Intuit Lacerte 2017 has Incorrect Access Control. | |||||
CVE-2019-1010316 | 1 Pyxtrlock Project | 1 Pyxtrlock | 2019-07-14 | 4.6 MEDIUM | 7.8 HIGH |
pyxtrlock 0.3 and earlier is affected by: Incorrect Access Control. The impact is: False locking impression when run in a non-X11 session. The fixed version is: 0.4. | |||||
CVE-2018-17151 | 1 Intersystems | 1 Cache | 2019-07-12 | 5.5 MEDIUM | 5.4 MEDIUM |
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control. | |||||
CVE-2018-19576 | 1 Gitlab | 1 Gitlab | 2019-07-11 | 6.4 MEDIUM | 8.1 HIGH |
GitLab CE/EE, versions 8.6 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an access control issue that allows a Guest user to make changes to or delete their own comments on an issue, after the issue was made Confidential. | |||||
CVE-2018-19496 | 1 Gitlab | 1 Gitlab | 2019-07-11 | 4.0 MEDIUM | 6.5 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone. | |||||
CVE-2018-19494 | 1 Gitlab | 1 Gitlab | 2019-07-11 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names. | |||||
CVE-2018-14859 | 1 Odoo | 1 Odoo | 2019-07-10 | 5.5 MEDIUM | 8.1 HIGH |
Incorrect access control in the password reset component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated users to reset the password of other users by being the first party to use the secure token. | |||||
CVE-2016-2787 | 2 Puppet, Puppetlabs | 2 Puppet Enterprise, Puppet Enterprise | 2019-07-10 | 5.0 MEDIUM | 5.3 MEDIUM |
The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which allows remote non-whitelisted hosts to prevent runs from triggering via unspecified vectors. | |||||
CVE-2019-13028 | 1 Minv | 1 Electronic Identification Cards Client | 2019-07-05 | 6.8 MEDIUM | 8.8 HIGH |
An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the Ministry of Interior of the Slovak Republic. | |||||
CVE-2018-14863 | 1 Odoo | 1 Odoo | 2019-07-05 | 5.5 MEDIUM | 8.1 HIGH |
Incorrect access control in the RPC framework in Odoo Community 8.0 through 11.0 and Odoo Enterprise 9.0 through 11.0 allows authenticated users to call private functions via RPC. | |||||
CVE-2018-14864 | 1 Odoo | 1 Odoo | 2019-07-05 | 4.0 MEDIUM | 6.5 MEDIUM |
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment. | |||||
CVE-2018-14885 | 1 Odoo | 1 Odoo | 2019-07-05 | 7.5 HIGH | 9.8 CRITICAL |
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds. | |||||
CVE-2018-14867 | 1 Odoo | 1 Odoo | 2019-07-05 | 5.0 MEDIUM | 5.3 MEDIUM |
Incorrect access control in the portal messaging system in Odoo Community 9.0 and 10.0 and Odoo Enterprise 9.0 and 10.0 allows remote attackers to post messages on behalf of customers, and to guess document attribute values, via crafted parameters. | |||||
CVE-2018-17148 | 1 Nagios | 1 Nagios Xi | 2019-06-21 | 5.0 MEDIUM | 9.8 CRITICAL |
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials. | |||||
CVE-2018-16553 | 1 Jspxcms | 1 Jspxcms | 2019-06-21 | 6.5 MEDIUM | 7.2 HIGH |
In Jspxcms 9.0.0, a vulnerable URL routing implementation allows remote code execution after logging in as web admin. | |||||
CVE-2017-10721 | 1 Ishekar | 2 Endoscope Camera, Endoscope Camera Firmware | 2019-06-20 | 4.0 MEDIUM | 6.5 MEDIUM |
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has Telnet functionality enabled by default. This device acts as an Endoscope camera that allows its users to use it in various industrial systems and settings, car garages, and also in some cases in the medical clinics to get access to areas that are difficult for a human being to reach. Any breach of this system can allow an attacker to get access to video feed and pictures viewed by that user and might allow them to get a foot hold in air gapped networks especially in case of nation critical infrastructure/industries. | |||||
CVE-2018-18958 | 1 Opnsense | 1 Opnsense | 2019-06-19 | 4.0 MEDIUM | 6.5 MEDIUM |
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control. |