← Back
CWE-277

71 CVEs • Abstraction: Variant

Insecure Inherited Permissions

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

JSON object

Loading...

CVEs (71)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Nuc P14e Laptop Element
Jun 17, 2026
May 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege...Show more
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Intel
1Vtune Profiler
Jun 17, 2026
May 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Intel
1Nuc Software Studio Service
Jun 17, 2026
May 10, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access
1Extplorer
1Extplorer
Jun 17, 2026
Mar 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent
1Intel
1Nuc Kit Wireless Adapter Driver Installer
Jun 17, 2026
Nov 11, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable e...Show more
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.Show less
1Neoan
1Neoan3 Template
Jun 17, 2026
Nov 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template...Show more
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue arises if a value has the same name as a method or function in scope and can therefore be executed either by mistake or maliciously. In theory all users of the package are affected as long as they either deal with direct user input or database values. A multi-step attack on is therefore plausible. Version 1.1.1 has addressed this vulnerability. Unfortunately only working with hardcoded values is safe in prior versions. As this likely defeats the purpose of a template engine, please upgrade.Show less
1Nextcloud
1Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The iss...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
1Facebook
1Zstandard
Jun 17, 2026
Mar 4, 2021
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwar...Show more
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or writable to unintended parties.Show less
1Facebook
1Zstandard
Jun 17, 2026
Mar 4, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore...Show more
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.Show less
1Dell
1Os Recovery Image For Microsoft Windows 10
Jun 17, 2026
May 4, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges cou...Show more
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vulnerability to gain unauthorized access on the root folder.Show less
4Canonical
DebianMesa3d+1 more
4Debian Linux
LeapMesa+1 more
Jun 17, 2026
Nov 5, 2019
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnera...Show more
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.Show less