CVE-2017-2694

CVSS v3 Score
3.3
Low
CVSS v2 Score
4.3
Medium

Vulnerability Description

The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert music will be played suddenly, compromising user experience.

CVSS:3.3(Low)

IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.

CVSS:3.3(Low)

cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).

CVSS:3.3(Low)

IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.

CVSS:3.3(Low)

The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from p...

CVSS:3.3(Low)

cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).

CVSS:3.3(Low)

In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).