Search Results (1866 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-41942 1 Jupyter 1 Jupyterhub 2024-08-12 7.2 High
JupyterHub is software that allows one to create a multi-user server for Jupyter notebooks. Prior to versions 4.1.6 and 5.1.0, if a user is granted the `admin:users` scope, they may escalate their own privileges by making themselves a full admin user. The impact is relatively small in that `admin:users` is already an extremely privileged scope only granted to trusted users. In effect, `admin:users` is equivalent to `admin=True`, which is not intended. Note that the change here only prevents escalation to the built-in JupyterHub admin role that has unrestricted permissions. It does not prevent users with e.g. `groups` permissions from granting themselves or other users permissions via group membership, which is intentional. Versions 4.1.6 and 5.1.0 fix this issue.
CVE-2011-4361 2 Debian, Mediawiki 2 Debian Linux, Mediawiki 2024-08-07 N/A
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.
CVE-2011-3350 1 Marmaro 1 Masqmail 2024-08-06 9.8 Critical
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-2921 1 Ktsuss Project 1 Ktsuss 2024-08-06 9.8 Critical
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CVE-2011-2859 1 Google 1 Chrome 2024-08-06 N/A
Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
CVE-2011-2782 2 Google, Linux 2 Chrome, Linux Kernel 2024-08-06 N/A
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
CVE-2011-1762 1 Wordpress 1 Wordpress 2024-08-06 6.5 Medium
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permission.
CVE-2011-1435 1 Google 1 Chrome 2024-08-06 N/A
Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.
CVE-2012-6136 3 Debian, Fedoraproject, Redhat 7 Debian Linux, Fedora, Enterprise Linux and 4 more 2024-08-06 5.5 Medium
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
CVE-2012-5578 1 Python 1 Keyring 2024-08-06 6.2 Medium
Python keyring has insecure permissions on new databases allowing world-readable files to be created
CVE-2012-5628 1 Gofer Project 1 Gofer 2024-08-06 N/A
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
CVE-2012-5577 2 Debian, Python 2 Debian Linux, Keyring 2024-08-06 7.5 High
Python keyring lib before 0.10 created keyring files with world-readable permissions.
CVE-2012-4453 3 Dracut Project, Fedoraproject, Redhat 6 Dracut, Fedora, Enterprise Linux and 3 more 2024-08-06 N/A
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
CVE-2012-4434 1 Cipherdyne 1 Fwknop 2024-08-06 8.8 High
fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.
CVE-2012-1187 1 Bitlbee 1 Bitlbee 2024-08-06 9.8 Critical
Bitlbee does not drop extra group privileges correctly in unix.c
CVE-2012-1157 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-08-06 4.3 Medium
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
CVE-2024-7458 2 Eladmin, Elunez 2 Eladmin, Eladmin 2024-08-06 5.5 Medium
A vulnerability was found in elunez eladmin up to 2.7 and classified as critical. This issue affects some unknown processing of the file /api/deploy/upload /api/database/upload of the component Database Management/Deployment Management. The manipulation of the argument file leads to path traversal: 'dir/../../filename'. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-273551.
CVE-2013-4859 1 Insteon 2 Hub, Hub Firmware 2024-08-06 8.1 High
INSTEON Hub 2242-222 lacks Web and API authentication
CVE-2013-4764 1 Samsung 4 Galaxy S3, Galaxy S3 Firmware, Galaxy S4 and 1 more 2024-08-06 4.3 Medium
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
CVE-2013-4763 1 Samsung 4 Galaxy S3, Galaxy S3 Firmware, Galaxy S4 and 1 more 2024-08-06 4.6 Medium
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.