CWE-732
1,663 CVEs • Abstraction: Class • Likelihood of Exploit: High
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
CVEs (1,663)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Foxitsoftware 2Foxit Reader PhantompdfNov 21, 2024 Oct 13, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 This vulnerability allows local attackers to escalate privileges on affected installations of Foxit Reader 10.0.0.35798. An attacker must first obtain the ability to execute low-privileged code on the target system in or...Show more |
4Apache DebianJunit+1 more4Communications Cloud Native Core Policy Debian LinuxJunit4+1 moreNov 21, 2024 Oct 12, 2020 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on tha...Show more |
2Debian Sympa2Debian Linux SympaNov 21, 2024 Oct 10, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 debian/sympa.postinst for the Debian Sympa package before 6.2.40~dfsg-7 uses mode 4755 for sympa_newaliases-wrapper, whereas the intended permissions are mode 4750 (for access by the sympa group) |
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. |
2Johnsoncontrols Tyco2C Cure Web Client Victor Web ClientNov 21, 2024 Oct 8, 2020 N/A· v4 8.1 HIGH· v3 7.8 HIGH· v2 A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or ren...Show more |
1Intel 1Driver & Support Assistant Nov 21, 2024 Oct 5, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access. |
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558). |
Improper directory permissions in the Hotspot Shield VPN client software for Windows 10.3.0 and earlier may allow an authorized user to potentially enable escalation of privilege via local access. The vulnerability allow...Show more |
A vulnerability in the file system permissions of Cisco IOS XE Software could allow an authenticated, local attacker to obtain read and write access to critical configuration or system files. The vulnerability is due to...Show more |
1Gogogate 1Ismartgate Pro Firmware Nov 21, 2024 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkUserExpirationDate.php. |
1Gogogate 1Ismartgate Pro Firmware Nov 21, 2024 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/checkExpirationDate.php. |
1Gogogate 1Ismartgate Pro Firmware Nov 21, 2024 Sep 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php. |
1Pingidentity 1Pingid Integration For Windows Login Nov 21, 2024 Sep 23, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 PingID Integration for Windows Login before 2.4.2 allows local users to gain privileges by modifying CefSharp.BrowserSubprocess.exe. |
WebAccess Node (All versions prior to 9.0.1) has incorrect permissions set for resources used by specific services, which may allow code execution with system privileges. |
1Microfocus 1Operation Bridge Reporter Nov 21, 2024 Sep 22, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The vulnerability could allow local attackers on the OBR host to execute code with escalated privileges...Show more |
An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user'...Show more |
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience. This flaw results in some users having access to sensitive information outside of their perm...Show more |
An issue was discovered in the DBI module through 1.643 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute in the data source name (DSN). NOTE: this issue...Show more |
2Debian Linux2Debian Linux Linux KernelNov 21, 2024 Sep 16, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read the /sys/class/zram-control/hot_add file can create ZRAM device nodes in the /dev/...Show more |
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute. |