CWE-278 · 7 записей
Insecure Preserved Inherited Permissions
CVE этого класса
7 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2025-2947Эксплойта нет | IBM i privilege escalationibm · i · CWE-278 | Критическая9,8 | — | 0,4 % | 17 апр. 2025 г. |
35Наблюдать | CVE-2024-36538Эксплойта нет | Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service accountchaos-mesh · chaos mesh · CWE-278 | Высокая8,8 | — | 0,6 % | 24 июл. 2024 г. |
35Наблюдать | CVE-2024-37769Эксплойта нет | Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.b1ackc4t · 14finger · CWE-278 | Высокая8,8 | — | 0,5 % | 5 июл. 2024 г. |
29Наблюдать | CVE-2023-38497Proof of concept | Cargo not respecting umask when extracting crate archivesrust-lang · cargo · CWE-278 | Высокая7,3 | — | 0,7 % | 4 авг. 2023 г. |
29Наблюдать | CVE-2026-6265Эксплойта нет | Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2cerberusftp · ftp server · CWE-278 | Высокая7,3 | — | 0,4 % | 27 апр. 2026 г. |
26Наблюдать | CVE-2026-71477Эксплойта нет | mise: Incorrect file ownership, when installed by the root user using `install.sh`jdx · mise · CWE-278 | Средняя6,7 | — | 0,1 % | 18 авг. 2026 г. |
14Наблюдать | CVE-2024-38531Эксплойта нет | Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible.nixos · nix · CWE-278 | Низкая3,6 | — | 0,1 % | 28 июн. 2024 г. |
- CVE-2025-294739Наблюдать
IBM i privilege escalation
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %ibm · i17 апр. 2025 г.
- CVE-2024-3653835Наблюдать
Insecure permissions in chaos-mesh v2.6.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %chaos-mesh · chaos mesh24 июл. 2024 г.
- CVE-2024-3776935Наблюдать
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator via a crafted POST request.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %b1ackc4t · 14finger5 июл. 2024 г.
- CVE-2023-3849729Наблюдать
Cargo not respecting umask when extracting crate archives
ВысокаяCVSS 7,3Proof of conceptEPSS 1 %rust-lang · cargo4 авг. 2023 г.
- CVE-2026-626529Наблюдать
Local Privilege Escalation in Cerberus FTP Server =< 2025.4.2
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %cerberusftp · ftp server27 апр. 2026 г.
- CVE-2026-7147726Наблюдать
mise: Incorrect file ownership, when installed by the root user using `install.sh`
СредняяCVSS 6,7Эксплойта нетEPSS 0 %jdx · mise18 авг. 2026 г.
- CVE-2024-3853114Наблюдать
Nix is a package manager for Linux and other Unix systems that makes package management reliable and reproducible.
НизкаяCVSS 3,6Эксплойта нетEPSS 0 %nixos · nix28 июн. 2024 г.