Vulnerabilities (CVE)

Filtered by CWE-275
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-18397 1 Cpanel 1 Cpanel 2019-08-13 2.1 LOW 3.3 LOW
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
CVE-2016-10796 1 Cpanel 1 Cpanel 2019-08-13 2.1 LOW 3.3 LOW
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
CVE-2017-18427 1 Cpanel 1 Cpanel 2019-08-12 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
CVE-2017-18425 1 Cpanel 1 Cpanel 2019-08-09 1.9 LOW 2.5 LOW
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
CVE-2017-18422 1 Cpanel 1 Cpanel 2019-08-06 2.1 LOW 3.3 LOW
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
CVE-2017-2694 1 Huawei 1 Vmall 2017-12-11 4.3 MEDIUM 3.3 LOW
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.
CVE-2016-7553 1 Irssi 1 Buf.pl 2017-03-15 2.1 LOW 3.3 LOW
The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.
CVE-2016-0394 1 Ibm 2 Integration Bus, Websphere Message Broker 2017-02-07 2.1 LOW 3.3 LOW
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
CVE-2016-2877 1 Ibm 1 Qradar Security Information And Event Manager 2016-12-23 2.1 LOW 3.3 LOW
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.