Vulnerabilities (CVE)

Filtered by CWE-552
Total 288 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-7737 1 Fortinet 1 Fortiweb 2019-10-03 4.0 MEDIUM 4.9 MEDIUM
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.
CVE-2017-11746 1 Inversepath 1 Tenshi 2019-10-03 7.8 HIGH 7.5 HIGH
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for tenshi.pid modification before a root script executes a "kill `cat /pathname/tenshi.pid`" command.
CVE-2017-6774 1 Cisco 1 Asr 5000 Software 2019-10-03 4.0 MEDIUM 5.0 MEDIUM
A vulnerability in Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify sensitive system files. The vulnerability is due to the inclusion of sensitive system files within specific FTP subdirectories. An attacker could exploit this vulnerability by overwriting sensitive configuration files through FTP. An exploit could allow the attacker to overwrite configuration files on an affected system. Cisco Bug IDs: CSCvd47739. Known Affected Releases: 21.0.v0.65839.
CVE-2017-11829 1 Microsoft 2 Windows 10, Windows Server 2016 2019-10-03 2.1 LOW 5.5 MEDIUM
Microsoft Windows 10 allows an elevation of privilege vulnerability when the Windows Update Delivery Optimization does not properly enforce file share permissions.
CVE-2017-1308 1 Ibm 1 Daeja Viewone 2019-10-03 4.0 MEDIUM 6.5 MEDIUM
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.
CVE-2019-14273 1 Silverstripe 1 Silverstripe 2019-09-27 5.0 MEDIUM 5.3 MEDIUM
In SilverStripe assets 4.0, there is broken access control on files.
CVE-2016-10829 1 Cpanel 1 Cpanel 2019-08-12 6.8 MEDIUM 6.5 MEDIUM
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
CVE-2017-2551 1 Inpsyde 1 Backwpup 2017-10-10 5.0 MEDIUM 7.5 HIGH
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup file for download.