CWE-732
1,702 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVEs (1,702)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Dovecot OpensuseRedhat4Dovecot Enterprise LinuxLeap+1 moreNov 21, 2024 Nov 5, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. |
In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially b...Show more |
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'. |
2Apache Redhat2Jboss Enterprise Web Server StrutsNov 21, 2024 Nov 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exc...Show more |
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725. |
1Redhat 1Jboss Operations Network Nov 21, 2024 Oct 30, 2019 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the pri...Show more |
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which cau...Show more |
1Zenspider 1Ruby Parser Legacy Jun 17, 2026 Oct 24, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a lo...Show more |
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365. |
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. |
1Intel 1Smart Connect Technology Jun 17, 2026 Oct 11, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. |
An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable. |
1Softing 1Uagate Si Firmware Jun 17, 2026 Oct 10, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specifi...Show more |
1Microsoft 1Windows 10 Update Assistant Jun 17, 2026 Oct 10, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 U...Show more |
1Dell 2Emc Avamar Server Emc Integrated Data Protection ApplianceJun 17, 2026 Oct 9, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2.3 and 2.4 contain an Incorrect Permission Assignment for Critical Reso...Show more |
The PKI keys exported using the command "run request security pki key-pair export" on Junos OS may have insecure file permissions. This may allow another user on the Junos OS device with shell access to read them. This i...Show more |
2Isc Redhat2Bind Enterprise LinuxJun 17, 2026 Oct 9, 2019 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.5-P2, 9.12.0 -> 9.12.3-P2, and versions 9....Show more |
1Orbisius 1Child Theme Creator Nov 21, 2024 Oct 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The orbisius-child-theme-creator plugin before 1.2.8 for WordPress has incorrect access control for file modification via the wp-admin/admin-ajax.php?action=orbisius_ctc_theme_editor_ajax&sub_cmd=save_file theme_1, theme...Show more |
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted T...Show more |