← Back
CWE-732

1,744 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

JSON object

Loading...

CVEs (1,744)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Artifex
FedoraprojectOpensuse
3Fedora
GhostscriptLeap
Jun 17, 2026
Nov 15, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker coul...Show more
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access files outside of restricted areas or execute commands.Show less
1Mi
1Redmi 6 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.f...Show more
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006) that allows any app co-located on the device to programmatically disable and enable Wi-Fi, Bluetooth, and GPS without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Z60s Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versi...Show more
The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Iris 88 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (...Show more
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Z81 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionN...Show more
The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Z61 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (version...Show more
The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Z92 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionN...Show more
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Iris 88 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versio...Show more
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Lavamobiles
1Flair Z1 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versi...Show more
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.Show less
1Intel
1Proset/wireless Wifi
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.
1Intel
1Proset/wireless Wifi
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
1Scanguard
1Scanguard Antivirus
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
1Microsoft
1Office
Jun 17, 2026
Nov 12, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.
1Drupal
1Svg Sanitizer
Jun 17, 2026
Nov 11, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
1Medtronic
2Valleylab Ft10 Energy Platform Firmware
Valleylab Ls10 Energy Platform Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the...Show more
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.Show less
1Zte
1Zxupn 9000e Firmware
Jun 17, 2026
Nov 8, 2019
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change pas...Show more
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control. An attacker could exploit this vulnerability to directly reset or change passwords of other accounts.Show less
1Redhat
1Openstack Mistral
Jun 17, 2026
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access se...Show more
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.Show less
3Debian
FedoraprojectRedhat
3389 Directory Server
Debian LinuxEnterprise Linux
Jun 17, 2026
Nov 8, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more
A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes, such as password hashes.Show less
2Debian
Viewvc
2Debian Linux
Viewvc
Nov 21, 2024
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.