CWE-279 · 25 записей
Incorrect Execution-Assigned Permissions
CVE этого класса
25 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-37734Эксплойта нет | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.open-emr · openemr · CWE-279 | Критическая9,8 | — | 0,8 % | 26 июн. 2024 г. |
37Наблюдать | CVE-2020-8025Эксплойта нет | outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issuessuse · linux enterprise high performance computing · CWE-279 | Критическая9,3 | — | 0,5 % | 7 авг. 2020 г. |
35Наблюдать | CVE-2023-4665Эксплойта нет | Privilage Escalation in Saphira Connectadobe · connect · CWE-279 | Высокая8,8 | — | 1,0 % | 15 сент. 2023 г. |
35Наблюдать | CVE-2025-22843Эксплойта нет | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Высокая8,8 | — | 0,1 % | 13 мая 2025 г. |
34Наблюдать | CVE-2025-14025Эксплойта нет | Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictionsred hat · red hat ansible automation platform 2.5 for rhel 8 · CWE-279 | Высокая8,5 | — | 0,4 % | 8 янв. 2026 г. |
34Наблюдать | CVE-2024-11220Эксплойта нет | Open Automation Software Incorrect Execution-Assigned Permissionsopenautomationsoftware · open automation software · CWE-279 | Высокая8,5 | — | 0,2 % | 6 дек. 2024 г. |
31Наблюдать | CVE-2023-4383Эксплойта нет | MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissionsescanav · escan anti-virus · CWE-279 | Высокая7,8 | — | 0,3 % | 16 авг. 2023 г. |
31Наблюдать | CVE-2024-25621Эксплойта нет | containerd affected by a local privilege escalation via wide permissions on CRI directorylinuxfoundation · containerd · CWE-279 | Высокая7,8 | — | 0,2 % | 6 нояб. 2025 г. |
30Наблюдать | CVE-2025-23263Эксплойта нет | NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privilegnvidia · doca-host and mellanox ofed · CWE-279 | Высокая7,6 | — | 0,2 % | 17 июл. 2025 г. |
29Наблюдать | CVE-2025-30001Эксплойта нет | Apache StreamPark: Authenticated users can trigger remote command executionapache · streampark · CWE-279 | Высокая7,3 | — | 0,6 % | 10 окт. 2025 г. |
28Наблюдать | CVE-2023-3915Эксплойта нет | Incorrect Execution-Assigned Permissions in GitLabgitlab · gitlab · CWE-279 | Высокая7,2 | — | 0,7 % | 1 сент. 2023 г. |
28Наблюдать | CVE-2026-20062Эксплойта нет | A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authecisco · cisco secure firewall adaptive security appliance (asa) software · CWE-279 | Высокая7,2 | — | 0,1 % | 4 мар. 2026 г. |
26Наблюдать | CVE-2023-50914Эксплойта нет | A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authenticCWE-279 | Средняя6,7 | — | 0,7 % | 30 апр. 2024 г. |
26Наблюдать | CVE-2025-12801Эксплойта нет | Nfs-utils: rpc.mountd in the nfs-utils privilege escalationredhat · openshift container platform · CWE-279 | Средняя6,5 | — | 0,5 % | 4 мар. 2026 г. |
22Наблюдать | CVE-2026-4948Эксплойта нет | Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorizationfirewalld · firewalld · CWE-279 | Средняя5,5 | — | 0,2 % | 27 мар. 2026 г. |
21Наблюдать | CVE-2024-37025Эксплойта нет | Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 mCWE-279 | Средняя5,4 | — | 0,2 % | 13 нояб. 2024 г. |
21Наблюдать | CVE-2025-13663Эксплойта нет | Quartus Prime Pro Edition Installer Advisoryintel · quartus prime · CWE-279 | Средняя5,4 | — | 0,1 % | 11 дек. 2025 г. |
20Наблюдать | CVE-2025-20612Эксплойта нет | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Средняя5,1 | — | 0,2 % | 13 мая 2025 г. |
20Наблюдать | CVE-2025-23233Эксплойта нет | Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated usCWE-279 | Средняя5,1 | — | 0,2 % | 13 мая 2025 г. |
17Наблюдать | CVE-2017-8441Эксплойта нет | Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.elastic · x-pack · CWE-279 | Средняя4,3 | — | 0,7 % | 5 июн. 2017 г. |
17Наблюдать | CVE-2026-46388Эксплойта нет | osquery: Unprivileged users can temporarily read file carve contentsosquery · osquery · CWE-279 | Средняя4,4 | — | 0,1 % | 10 июл. 2026 г. |
16Наблюдать | CVE-2025-26422Эксплойта нет | In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permissiongoogle · android · CWE-279 | Средняя4,0 | — | 0,1 % | 4 сент. 2025 г. |
15Наблюдать | CVE-2025-36228Эксплойта нет | Incorrect Execution-Assigned Permissions in IBM Aspera Faspexibm · aspera faspex · CWE-279 | Низкая3,8 | — | 0,2 % | 26 дек. 2025 г. |
8Наблюдать | CVE-2024-39286Эксплойта нет | Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 mCWE-279 | Низкая2,0 | — | 0,2 % | 12 февр. 2025 г. |
8Наблюдать | GHSA-qc59-cxj2-c2w4Эксплойта нет | aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Rolenpm · aws-cdk-lib · CWE-279 | Низкая2,2 | — | — | 15 апр. 2025 г. |
- CVE-2024-3773439Наблюдать
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %open-emr · openemr26 июн. 2024 г.
- CVE-2020-802537Наблюдать
outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %suse · linux enterprise high performance computing7 авг. 2020 г.
- CVE-2023-466535Наблюдать
Privilage Escalation in Saphira Connect
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %adobe · connect15 сент. 2023 г.
- CVE-2025-2284335Наблюдать
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %13 мая 2025 г.
- CVE-2025-1402534Наблюдать
Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %red hat · red hat ansible automation platform 2.5 for rhel 88 янв. 2026 г.
- CVE-2024-1122034Наблюдать
Open Automation Software Incorrect Execution-Assigned Permissions
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %openautomationsoftware · open automation software6 дек. 2024 г.
- CVE-2023-438331Наблюдать
MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %escanav · escan anti-virus16 авг. 2023 г.
- CVE-2024-2562131Наблюдать
containerd affected by a local privilege escalation via wide permissions on CRI directory
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linuxfoundation · containerd6 нояб. 2025 г.
- CVE-2025-2326330Наблюдать
NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %nvidia · doca-host and mellanox ofed17 июл. 2025 г.
- CVE-2025-3000129Наблюдать
Apache StreamPark: Authenticated users can trigger remote command execution
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %apache · streampark10 окт. 2025 г.
- CVE-2023-391528Наблюдать
Incorrect Execution-Assigned Permissions in GitLab
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %gitlab · gitlab1 сент. 2023 г.
- CVE-2026-2006228Наблюдать
A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %cisco · cisco secure firewall adaptive security appliance (asa) software4 мар. 2026 г.
- CVE-2023-5091426Наблюдать
A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic
СредняяCVSS 6,7Эксплойта нетEPSS 1 %30 апр. 2024 г.
- CVE-2025-1280126Наблюдать
Nfs-utils: rpc.mountd in the nfs-utils privilege escalation
СредняяCVSS 6,5Эксплойта нетEPSS 0 %redhat · openshift container platform4 мар. 2026 г.
- CVE-2026-494822Наблюдать
Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
СредняяCVSS 5,5Эксплойта нетEPSS 0 %firewalld · firewalld27 мар. 2026 г.
- CVE-2024-3702521Наблюдать
Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m
СредняяCVSS 5,4Эксплойта нетEPSS 0 %13 нояб. 2024 г.
- CVE-2025-1366321Наблюдать
Quartus Prime Pro Edition Installer Advisory
СредняяCVSS 5,4Эксплойта нетEPSS 0 %intel · quartus prime11 дек. 2025 г.
- CVE-2025-2061220Наблюдать
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
СредняяCVSS 5,1Эксплойта нетEPSS 0 %13 мая 2025 г.
- CVE-2025-2323320Наблюдать
Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us
СредняяCVSS 5,1Эксплойта нетEPSS 0 %13 мая 2025 г.
- CVE-2017-844117Наблюдать
Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.
СредняяCVSS 4,3Эксплойта нетEPSS 1 %elastic · x-pack5 июн. 2017 г.
- CVE-2026-4638817Наблюдать
osquery: Unprivileged users can temporarily read file carve contents
СредняяCVSS 4,4Эксплойта нетEPSS 0 %osquery · osquery10 июл. 2026 г.
- CVE-2025-2642216Наблюдать
In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission
СредняяCVSS 4,0Эксплойта нетEPSS 0 %google · android4 сент. 2025 г.
- CVE-2025-3622815Наблюдать
Incorrect Execution-Assigned Permissions in IBM Aspera Faspex
НизкаяCVSS 3,8Эксплойта нетEPSS 0 %ibm · aspera faspex26 дек. 2025 г.
- CVE-2024-392868Наблюдать
Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m
НизкаяCVSS 2,0Эксплойта нетEPSS 0 %12 февр. 2025 г.
- GHSA-qc59-cxj2-c2w48Наблюдать
aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role
НизкаяCVSS 2,2Эксплойта нетnpm · aws-cdk-lib15 апр. 2025 г.