CWE-732
1,744 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVEs (1,744)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Anaconda Conda2Anaconda3 Miniconda3Jun 17, 2026 Mar 17, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Anaconda Anaconda3 (Anaconda Distribution) through 2021.11.0.0 and Miniconda3 through 4.11.0.0 can create a world-writable directory under %PROGRAMDATA% and place that directory into the system PATH environment variable....Show more |
A Incorrect Permission Assignment for Critical Resource vulnerability in the sudoers configuration in cscreen of openSUSE Factory allows any local users to gain the privileges of the tty and dialout groups and access and...Show more |
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system ad...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 'Root Service' service implemented in the following Yokogawa Electric products creates some named pipe with improper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versions from R4.01.00...Show more |
1Yokogawa 5Centum Cs 3000 Entry Firmware Centum Cs 3000 FirmwareCentum Vp Entry Firmware+2 moreJun 17, 2026 Mar 11, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 'Long-term Data Archive Package' service implemented in the following Yokogawa Electric products creates some named pipe with imporper ACL configuration. CENTUM CS 3000 versions from R3.08.10 to R3.09.00, CENTUM VP versi...Show more |
1Riverbed 1Steelcentral Appinternals Dynamic Sampling Agent Jun 17, 2026 Mar 10, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file to store a json string that contains a list of IDs and pre-configured commands. The config file is s...Show more |
1Bitdefender 4Antivirus Plus Endpoint Security ToolsInternet Security+1 moreJun 17, 2026 Mar 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used in Bitdefender Total Security, Internet Security, Antivirus Plus, Endpoint Security Tools for Windo...Show more |
2Netapp Redhat4Enterprise Linux LibvirtOntap Select Deploy Administration Utility+1 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one exploited guest to access files labeled for another guest, resulting in the breaking out of sVirt co...Show more |
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system. |
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions. |
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots. A local attacker could modify objects in the VMO that they do not have permission to. We recommend upgrading past commi...Show more |
2Argoproj Redhat2Argo Cd Openshift GitopsJun 17, 2026 Feb 16, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster i...Show more |
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53 |
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker...Show more |
2Kubernetes Redhat2Cri O Openshift Container PlatformJun 17, 2026 Feb 9, 2022 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier. The sysctls from the list of "safe" sysctls specified for the cluster will be applied to the host if an attacker is able to create a pod...Show more |
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability. |
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server. |
1Globalnorthstar 1Northstar Club Management Jun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication. |
Insertion of Sensitive Information into Log File in Conda loguru prior to 0.5.3. |
Incorrect Permission Assignment for Critical Resource in Packagist microweber/microweber prior to 1.2.11. |