CWE-277 · 66 записей
Insecure Inherited Permissions
CVE этого класса
66 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-36539Proof of concept | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account'sprojectcontour · contour · CWE-277 | Критическая9,8 | — | 1,3 % | 24 июл. 2024 г. |
39Наблюдать | CVE-2024-36540Эксплойта нет | Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service external-secrets · external secrets operator · CWE-277 | Критическая9,8 | — | 0,4 % | 24 июл. 2024 г. |
36Наблюдать | CVE-2023-27842Proof of concept | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code viaextplorer · extplorer · CWE-277 | Высокая8,8 | — | 2,4 % | 21 мар. 2023 г. |
35Наблюдать | CVE-2024-36542Эксплойта нет | Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tokCWE-277 | Высокая8,8 | — | 0,5 % | 25 июл. 2024 г. |
35Наблюдать | CVE-2024-6605Эксплойта нет | Firefox Android missed activation delay to prevent tapjackingmozilla · firefox · CWE-277 | Высокая8,8 | — | 0,4 % | 9 июл. 2024 г. |
33Наблюдать | CVE-2024-7143Эксплойта нет | Pulpcore: rbac permissions incorrectly assigned in tasks that create objectspulpproject · pulp · CWE-277 | Высокая8,3 | — | 0,6 % | 7 авг. 2024 г. |
33Наблюдать | CVE-2024-34329Proof of concept | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticatedCWE-277 | Высокая8,4 | — | 0,6 % | 22 июл. 2024 г. |
33Наблюдать | CVE-2024-29417Эксплойта нет | Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password resCWE-277 | Высокая8,4 | — | 0,2 % | 3 мая 2024 г. |
32Наблюдать | CVE-2025-58437Эксплойта нет | Coder's privilege escalation vulnerability could lead to a cross workspace compromisecoder · coder · CWE-277 | Высокая8,1 | — | 0,4 % | 5 сент. 2025 г. |
31Наблюдать | CVE-2024-27822Готовый эксплойт | A logic issue was addressed with improved restrictions.apple · macos · CWE-277 | Высокая7,8 | — | 1,5 % | 14 мая 2024 г. |
31Наблюдать | CVE-2020-5343Эксплойта нет | Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissdell · os recovery image for microsoft windows 10 · CWE-277 | Высокая7,8 | — | 0,3 % | 4 мая 2020 г. |
31Наблюдать | CVE-2024-23233Эксплойта нет | This issue was addressed with improved checks.apple · macos · CWE-277 | Высокая7,8 | — | 0,2 % | 7 мар. 2024 г. |
31Наблюдать | CVE-2023-34314Эксплойта нет | Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentiallintel · simics simulator · CWE-277 | Высокая7,8 | — | 0,2 % | 14 нояб. 2023 г. |
31Наблюдать | CVE-2023-39230Эксплойта нет | Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user intel · rapid storage technology · CWE-277 | Высокая7,8 | — | 0,2 % | 14 нояб. 2023 г. |
31Наблюдать | CVE-2023-34997Эксплойта нет | Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authintel · server configuration utility · CWE-277 | Высокая7,8 | — | 0,2 % | 14 нояб. 2023 г. |
31Наблюдать | CVE-2023-45736Эксплойта нет | Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enaintel · power gadget · CWE-277 | Высокая7,8 | — | 0,2 % | 16 мая 2024 г. |
31Наблюдать | CVE-2026-30266Эксплойта нет | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafdeepcool · deepcreative · CWE-277 | Высокая7,8 | — | 0,2 % | 20 апр. 2026 г. |
31Наблюдать | CVE-2022-33898Эксплойта нет | Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated intel · nuc watchdog timer utility · CWE-277 | Высокая7,8 | — | 0,2 % | 14 нояб. 2023 г. |
31Наблюдать | CVE-2023-33870Эксплойта нет | Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enintel · administrative tools for intel network adapters · CWE-277 | Высокая7,8 | — | 0,2 % | 14 февр. 2024 г. |
31Наблюдать | CVE-2022-41700Эксплойта нет | Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatintel · nuc pro software suite · CWE-277 | Высокая7,8 | — | 0,2 % | 14 нояб. 2023 г. |
31Наблюдать | CVE-2024-21835Эксплойта нет | Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable intel · extreme tuning utility · CWE-277 | Высокая7,8 | — | 0,2 % | 16 мая 2024 г. |
31Наблюдать | CVE-2022-46656Эксплойта нет | Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentiallyintel · nuc pro software suite · CWE-277 | Высокая7,8 | — | 0,1 % | 10 мая 2023 г. |
31Наблюдать | CVE-2022-38103Эксплойта нет | Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated useintel · nuc software studio service · CWE-277 | Высокая7,8 | — | 0,1 % | 10 мая 2023 г. |
31Наблюдать | CVE-2022-41687Эксплойта нет | Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4intel · nuc p14e laptop element · CWE-277 | Высокая7,8 | — | 0,1 % | 10 мая 2023 г. |
31Наблюдать | CVE-2022-41658Эксплойта нет | Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentiaintel · vtune profiler · CWE-277 | Высокая7,8 | — | 0,1 % | 10 мая 2023 г. |
- CVE-2024-3653939Наблюдать
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
КритическаяCVSS 9,8Proof of conceptEPSS 1 %projectcontour · contour24 июл. 2024 г.
- CVE-2024-3654039Наблюдать
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %external-secrets · external secrets operator24 июл. 2024 г.
- CVE-2023-2784236Наблюдать
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %extplorer · extplorer21 мар. 2023 г.
- CVE-2024-3654235Наблюдать
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tok
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %25 июл. 2024 г.
- CVE-2024-660535Наблюдать
Firefox Android missed activation delay to prevent tapjacking
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mozilla · firefox9 июл. 2024 г.
- CVE-2024-714333Наблюдать
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %pulpproject · pulp7 авг. 2024 г.
- CVE-2024-3432933Наблюдать
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated
ВысокаяCVSS 8,4Proof of conceptEPSS 1 %22 июл. 2024 г.
- CVE-2024-2941733Наблюдать
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password res
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %3 мая 2024 г.
- CVE-2025-5843732Наблюдать
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %coder · coder5 сент. 2025 г.
- CVE-2024-2782231Наблюдать
A logic issue was addressed with improved restrictions.
ВысокаяCVSS 7,8Готовый эксплойтEPSS 1 %apple · macos14 мая 2024 г.
- CVE-2020-534331Наблюдать
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permiss
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %dell · os recovery image for microsoft windows 104 мая 2020 г.
- CVE-2024-2323331Наблюдать
This issue was addressed with improved checks.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %apple · macos7 мар. 2024 г.
- CVE-2023-3431431Наблюдать
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentiall
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · simics simulator14 нояб. 2023 г.
- CVE-2023-3923031Наблюдать
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · rapid storage technology14 нояб. 2023 г.
- CVE-2023-3499731Наблюдать
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an auth
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · server configuration utility14 нояб. 2023 г.
- CVE-2023-4573631Наблюдать
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially ena
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · power gadget16 мая 2024 г.
- CVE-2026-3026631Наблюдать
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a craf
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %deepcool · deepcreative20 апр. 2026 г.
- CVE-2022-3389831Наблюдать
Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · nuc watchdog timer utility14 нояб. 2023 г.
- CVE-2023-3387031Наблюдать
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially en
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · administrative tools for intel network adapters14 февр. 2024 г.
- CVE-2022-4170031Наблюдать
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticat
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · nuc pro software suite14 нояб. 2023 г.
- CVE-2024-2183531Наблюдать
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · extreme tuning utility16 мая 2024 г.
- CVE-2022-4665631Наблюдать
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · nuc pro software suite10 мая 2023 г.
- CVE-2022-3810331Наблюдать
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated use
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · nuc software studio service10 мая 2023 г.
- CVE-2022-4168731Наблюдать
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · nuc p14e laptop element10 мая 2023 г.
- CVE-2022-4165831Наблюдать
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentia
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %intel · vtune profiler10 мая 2023 г.