Vulnerabilities > Permissions, Privileges, and Access Controls

DATE CVE VULNERABILITY TITLE RISK
2017-09-07 CVE-2015-4629 Permissions, Privileges, and Access Controls vulnerability in Huawei E5756S Firmware V100R001B100D00Sp00C00
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perform other unspecified actions.
network
low complexity
huawei CWE-264
critical
9.8
2017-09-07 CVE-2015-3222 Permissions, Privileges, and Access Controls vulnerability in Ossec
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
local
high complexity
ossec CWE-264
7.0
2017-09-07 CVE-2015-1590 Permissions, Privileges, and Access Controls vulnerability in Kamailio
The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
local
low complexity
kamailio CWE-264
7.8
2017-08-29 CVE-2013-7432 Permissions, Privileges, and Access Controls vulnerability in Mapsplugin Googlemaps 3.0
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
network
low complexity
mapsplugin CWE-264
7.5
2017-08-29 CVE-2016-2959 Permissions, Privileges, and Access Controls vulnerability in IBM Sametime
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges.
network
low complexity
ibm CWE-264
4.3
2017-08-28 CVE-2014-8428 Permissions, Privileges, and Access Controls vulnerability in Barracuda Load Balancer 5.0.0.015
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
network
low complexity
barracuda CWE-264
critical
9.8
2017-08-25 CVE-2015-1324 Permissions, Privileges, and Access Controls vulnerability in Canonical Ubuntu Linux
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.
local
low complexity
canonical CWE-264
7.8
2017-08-22 CVE-2015-3617 Permissions, Privileges, and Access Controls vulnerability in Fortinet Fortimanager Firmware
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
local
low complexity
fortinet CWE-264
7.8
2017-08-18 CVE-2015-4082 Permissions, Privileges, and Access Controls vulnerability in Attic Project Attic
attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive information by changing the manifest type byte of the repository to "unencrypted / without key file".
network
low complexity
attic-project CWE-264
6.5
2017-08-18 CVE-2015-1878 Permissions, Privileges, and Access Controls vulnerability in Thalesesecurity Nshield Connect Firmware 11.30
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the nShield Connect device on a network, affect the integrity and confidentiality of newly created keys, and potentially cause other unspecified impacts using previously loaded keys by connecting to the USB port on the front panel.
low complexity
thalesesecurity CWE-264
6.8