CWE-732
1,658 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVEs (1,658)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can...Show more |
2Freeipa Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 Jul 27, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use...Show more |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jul 26, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information...Show more |
1Redhat 2Certification Enterprise LinuxNov 21, 2024 Jul 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 redhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any file accessible by the user running httpd. |
1F5 6Big Ip Domain Name System Big Ip Global Traffic ManagerBig Iq Centralized Management+3 moreNov 21, 2024 Jul 19, 2018 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 On F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.3, 11.6.0-11.6.3.1, or 11.5.1-11.5.6, Enterprise Manager 3.1.1, BIG-IQ Centralized Management 5.0.0-5.1.0, BIG-IQ Cloud and Orchestration 1.0.0, or F5 iWorkflow 2.1.0-2.3.0 the b...Show more |
1Cisco 3Mobility Services Engine 3310 Firmware Mobility Services Engine 3355 FirmwareMobility Services Engine 3365 FirmwareNov 21, 2024 Jul 18, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readab...Show more |
1Doorkeeper Project 1Doorkeeper Nov 21, 2024 Jul 13, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Doorkeeper version 4.2.0 and later contains a Incorrect Access Control vulnerability in Token revocation API's authorized method that can result in Access tokens are not revoked for public OAuth apps, leaking access unti...Show more |
Sensu, Inc. Sensu Core version Before version 1.4.2-3 contains a Insecure Permissions vulnerability in Sensu Core on Windows platforms that can result in Unprivileged users may execute code in context of Sensu service ac...Show more |
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpthumb class that can result in Creating file with custom a filename and content....Show more |
mstdlib (aka the M Standard Library for C) 1.2.0 has incorrect file access control in situations where M_fs_perms_can_access attempts to delete an existing file (that lacks public read/write access) during a copy operati...Show more |
1Wago 4762 3000 Firmware 762 3001 Firmware762 3002 Firmware+1 moreNov 21, 2024 Jul 12, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in...Show more |
It was discovered in the Linux kernel before 4.11-rc8 that root can gain direct access to an internal keyring, such as '.dns_resolver' in RHEL-7 or '.builtin_trusted_keys' upstream, by joining it as its session keyring....Show more |
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter. |
Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosu...Show more |
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System (9pfs) support, is vulnerable to an improper access control issue. It could occur while accessing files on a shared host director...Show more |
1Qualcomm 38Mdm9206 Firmware Mdm9607 FirmwareMdm9635m Firmware+35 moreNov 21, 2024 Jul 6, 2018 N/A· v4 7.7 HIGH· v3 3.6 LOW· v2 Due to Improper Access Control of NAND-based EFS in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear, From fastboot on a NAND-based device, the EFS partition can be erased. Apps processor then has non-secure...Show more |
1Adbglobal 4Dv2210 Firmware Prg Av4202n FirmwareVv2220 Firmware+1 moreNov 21, 2024 Jul 6, 2018 N/A· v4 7.5 HIGH· v3 8.5 HIGH· v2 All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the...Show more |
onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI. |
Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation r...Show more |
Incorrect Permission Assignment on the /var/www/xms/cleanzip.sh shell script run periodically in Dialogic PowerMedia XMS through 3.5 allows local users to execute code as the root user. |