Vulnerabilities > Permissions, Privileges, and Access Controls

DATE CVE VULNERABILITY TITLE RISK
2017-09-19 CVE-2014-9610 Permissions, Privileges, and Access Controls vulnerability in Netsweeper
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user/quarantine_disable.php.
network
low complexity
netsweeper CWE-264
5.3
2017-09-11 CVE-2015-4523 Permissions, Privileges, and Access Controls vulnerability in Symantec Malware Analysis Appliance and Malware Analyzer G2
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.
local
low complexity
symantec CWE-264
critical
9.3
2017-09-07 CVE-2015-4629 Permissions, Privileges, and Access Controls vulnerability in Huawei E5756S Firmware V100R001B100D00Sp00C00
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perform other unspecified actions.
network
low complexity
huawei CWE-264
critical
9.8
2017-09-07 CVE-2015-3222 Permissions, Privileges, and Access Controls vulnerability in Ossec
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
local
high complexity
ossec CWE-264
7.0
2017-09-07 CVE-2015-1590 Permissions, Privileges, and Access Controls vulnerability in Kamailio
The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
local
low complexity
kamailio CWE-264
7.8
2017-08-29 CVE-2013-7432 Permissions, Privileges, and Access Controls vulnerability in Mapsplugin Googlemaps 3.0
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
network
low complexity
mapsplugin CWE-264
7.5
2017-08-29 CVE-2016-2959 Permissions, Privileges, and Access Controls vulnerability in IBM Sametime
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges.
network
low complexity
ibm CWE-264
4.3
2017-08-28 CVE-2014-8428 Permissions, Privileges, and Access Controls vulnerability in Barracuda Load Balancer 5.0.0.015
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
network
low complexity
barracuda CWE-264
critical
9.8
2017-08-25 CVE-2015-1324 Permissions, Privileges, and Access Controls vulnerability in Canonical Ubuntu Linux
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow local users to write to arbitrary files and gain root privileges by leveraging incorrect handling of permissions when generating core dumps for setuid binaries.
local
low complexity
canonical CWE-264
7.8
2017-08-22 CVE-2015-3617 Permissions, Privileges, and Access Controls vulnerability in Fortinet Fortimanager Firmware
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
local
low complexity
fortinet CWE-264
7.8