Skip to content
Noroxi

CWE-279 · 25 records

Incorrect Execution-Assigned Permissions

CVEs in this class

25 records

  • An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

    CriticalCVSS 9.8No exploitEPSS 1%

    open-emr · openemrJun 26, 2024

  • CVE-2020-8025
    37Monitor

    outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues

    CriticalCVSS 9.3No exploitEPSS 0%

    suse · linux enterprise high performance computingAug 7, 2020

  • CVE-2023-4665
    35Monitor

    Privilage Escalation in Saphira Connect

    HighCVSS 8.8No exploitEPSS 1%

    adobe · connectSep 15, 2023

  • Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    HighCVSS 8.8No exploitEPSS 0%

    May 13, 2025

  • Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions

    HighCVSS 8.5No exploitEPSS 0%

    red hat · red hat ansible automation platform 2.5 for rhel 8Jan 8, 2026

  • Open Automation Software Incorrect Execution-Assigned Permissions

    HighCVSS 8.5No exploitEPSS 0%

    openautomationsoftware · open automation softwareDec 6, 2024

  • CVE-2023-4383
    31Monitor

    MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions

    HighCVSS 7.8No exploitEPSS 0%

    escanav · escan anti-virusAug 16, 2023

  • containerd affected by a local privilege escalation via wide permissions on CRI directory

    HighCVSS 7.8No exploitEPSS 0%

    linuxfoundation · containerdNov 6, 2025

  • NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg

    HighCVSS 7.6No exploitEPSS 0%

    nvidia · doca-host and mellanox ofedJul 17, 2025

  • Apache StreamPark: Authenticated users can trigger remote command execution

    HighCVSS 7.3No exploitEPSS 1%

    apache · streamparkOct 10, 2025

  • CVE-2023-3915
    28Monitor

    Incorrect Execution-Assigned Permissions in GitLab

    HighCVSS 7.2No exploitEPSS 1%

    gitlab · gitlabSep 1, 2023

  • A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe

    HighCVSS 7.2No exploitEPSS 0%

    cisco · cisco secure firewall adaptive security appliance (asa) softwareMar 4, 2026

  • A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic

    MediumCVSS 6.7No exploitEPSS 1%

    Apr 30, 2024

  • Nfs-utils: rpc.mountd in the nfs-utils privilege escalation

    MediumCVSS 6.5No exploitEPSS 0%

    redhat · openshift container platformMar 4, 2026

  • CVE-2026-4948
    22Monitor

    Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

    MediumCVSS 5.5No exploitEPSS 0%

    firewalld · firewalldMar 27, 2026

  • Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m

    MediumCVSS 5.4No exploitEPSS 0%

    Nov 13, 2024

  • Quartus Prime Pro Edition Installer Advisory

    MediumCVSS 5.4No exploitEPSS 0%

    intel · quartus primeDec 11, 2025

  • Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    MediumCVSS 5.1No exploitEPSS 0%

    May 13, 2025

  • Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    MediumCVSS 5.1No exploitEPSS 0%

    May 13, 2025

  • CVE-2017-8441
    17Monitor

    Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.

    MediumCVSS 4.3No exploitEPSS 1%

    elastic · x-packJun 5, 2017

  • osquery: Unprivileged users can temporarily read file carve contents

    MediumCVSS 4.4No exploitEPSS 0%

    osquery · osqueryJul 10, 2026

  • In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission

    MediumCVSS 4.0No exploitEPSS 0%

    google · androidSep 4, 2025

  • Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

    LowCVSS 3.8No exploitEPSS 0%

    ibm · aspera faspexDec 26, 2025

  • Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m

    LowCVSS 2.0No exploitEPSS 0%

    Feb 12, 2025

  • aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role

    LowCVSS 2.2No exploit

    npm · aws-cdk-libApr 15, 2025

All vulnerability classes