← Back
CWE-281

337 CVEs • Abstraction: Base

Improper Preservation of Permissions

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

JSON object

Loading...

CVEs (337)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
6Ipados
Iphone OsMacos+3 more
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data...Show more
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, visionOS 2.2, watchOS 11.2. An app may be able to access sensitive user data.Show less
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2. An app may be able to access user-sensitive data.
1Apple
1Macos
Jun 17, 2026
Dec 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileges.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
4.6 MEDIUM· v3
N/A· v2
Silicon Labs Z-Wave Series 500 v6.84.0 was discovered to contain insecure permissions.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to arbitrarily change the device type in the controller's memory, leading to a Denial of Service (DoS).
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controlle...Show more
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to change the wakeup interval of end devices in controller memory, disrupting the device's communications with the controller.Show less
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the c...Show more
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the controller and the device itself via repeatedly sending crafted packets to the controller.Show less
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeatedly sending crafted packets to the controller.
1Silabs
1Z Wave Software Development Kit
Jun 17, 2026
Dec 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Insecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted packets.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.
1Openrobotics
1Robot Operating System
Jun 17, 2026
Dec 6, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.
-
-
Jun 17, 2026
Dec 4, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.miste...Show more
The Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the org.mistergroup.shouldianswer.ui.default_dialer.DefaultDialerActivity component.Show less
-
-
Jun 17, 2026
Nov 26, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating...Show more
lakeFS is an open-source tool that transforms object storage into a Git-like repository. Existing lakeFS users who have issued credentials to users who have been deleted are affected by this vulnerability. When creating a new user with the same username as a deleted user, that user will inherit all of the previous user's credentials. This issue has been addressed in release version 1.33.0 and all users are advised to upgrade. The only known workaround for those who cannot upgrade is to not reuse usernames.Show less
-
-
Jun 17, 2026
Nov 15, 2024
5.4 MEDIUM· v4
N/A· v3
N/A· v2
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivi...Show more
Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Insecure handling of symlinks with --links and --metadata in rclone while copying to local disk allows unprivileged users to indirectly modify ownership and permissions on symlink target files when a superuser or privileged process performs a copy. This vulnerability could enable privilege escalation and unauthorized access to critical system files, compromising system integrity, confidentiality, and availability. This vulnerability is fixed in 1.68.2.Show less
-
-
Jun 17, 2026
Nov 7, 2024
N/A· v4
4.0 MEDIUM· v3
N/A· v2
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted in...Show more
The com.callassistant.android (aka AI Call Assistant & Screener) application 1.174 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.callassistant.android.ui.call.incall.InCallActivity component.Show less