Перейти к содержимому
Noroxi

CWE-279 · 25 записей

Incorrect Execution-Assigned Permissions

CVE этого класса

25 записей

  • CVE-2024-37734
    39Наблюдать

    An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    open-emr · openemr26 июн. 2024 г.

  • CVE-2020-8025
    37Наблюдать

    outdated entries in permissions profiles for /var/lib/pcp/tmp/* may cause security issues

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    suse · linux enterprise high performance computing7 авг. 2020 г.

  • CVE-2023-4665
    35Наблюдать

    Privilage Escalation in Saphira Connect

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    adobe · connect15 сент. 2023 г.

  • CVE-2025-22843
    35Наблюдать

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    13 мая 2025 г.

  • CVE-2025-14025
    34Наблюдать

    Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    red hat · red hat ansible automation platform 2.5 for rhel 88 янв. 2026 г.

  • CVE-2024-11220
    34Наблюдать

    Open Automation Software Incorrect Execution-Assigned Permissions

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    openautomationsoftware · open automation software6 дек. 2024 г.

  • CVE-2023-4383
    31Наблюдать

    MicroWorld eScan Anti-Virus runasroot incorrect execution-assigned permissions

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    escanav · escan anti-virus16 авг. 2023 г.

  • CVE-2024-25621
    31Наблюдать

    containerd affected by a local privilege escalation via wide permissions on CRI directory

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    linuxfoundation · containerd6 нояб. 2025 г.

  • CVE-2025-23263
    30Наблюдать

    NVIDIA DOCA-Host and Mellanox OFED contain a vulnerability in the VGT+ feature, where an attacker on a VM might cause escalation of privileg

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    nvidia · doca-host and mellanox ofed17 июл. 2025 г.

  • CVE-2025-30001
    29Наблюдать

    Apache StreamPark: Authenticated users can trigger remote command execution

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    apache · streampark10 окт. 2025 г.

  • CVE-2023-3915
    28Наблюдать

    Incorrect Execution-Assigned Permissions in GitLab

    ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %

    gitlab · gitlab1 сент. 2023 г.

  • CVE-2026-20062
    28Наблюдать

    A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authe

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    cisco · cisco secure firewall adaptive security appliance (asa) software4 мар. 2026 г.

  • CVE-2023-50914
    26Наблюдать

    A Privilege Escalation issue in the inter-process communication procedure from GOG Galaxy (Beta) 2.0.67.2 through v2.0.71.2 allows authentic

    СредняяCVSS 6,7Эксплойта нетEPSS 1 %

    30 апр. 2024 г.

  • CVE-2025-12801
    26Наблюдать

    Nfs-utils: rpc.mountd in the nfs-utils privilege escalation

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    redhat · openshift container platform4 мар. 2026 г.

  • CVE-2026-4948
    22Наблюдать

    Firewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    firewalld · firewalld27 мар. 2026 г.

  • CVE-2024-37025
    21Наблюдать

    Incorrect execution-assigned permissions in some Intel(R) Advanced Link Analyzer Standard Edition software installer before version 23.1.1 m

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    13 нояб. 2024 г.

  • CVE-2025-13663
    21Наблюдать

    Quartus Prime Pro Edition Installer Advisory

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    intel · quartus prime11 дек. 2025 г.

  • CVE-2025-20612
    20Наблюдать

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    13 мая 2025 г.

  • CVE-2025-23233
    20Наблюдать

    Incorrect execution-assigned permissions for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an authenticated us

    СредняяCVSS 5,1Эксплойта нетEPSS 0 %

    13 мая 2025 г.

  • CVE-2017-8441
    17Наблюдать

    Elastic X-Pack Security versions prior to 5.4.1 and 5.3.3 did not always correctly apply Document Level Security to index aliases.

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    elastic · x-pack5 июн. 2017 г.

  • CVE-2026-46388
    17Наблюдать

    osquery: Unprivileged users can temporarily read file carve contents

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    osquery · osquery10 июл. 2026 г.

  • CVE-2025-26422
    16Наблюдать

    In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission

    СредняяCVSS 4,0Эксплойта нетEPSS 0 %

    google · android4 сент. 2025 г.

  • CVE-2025-36228
    15Наблюдать

    Incorrect Execution-Assigned Permissions in IBM Aspera Faspex

    НизкаяCVSS 3,8Эксплойта нетEPSS 0 %

    ibm · aspera faspex26 дек. 2025 г.

  • CVE-2024-39286
    8Наблюдать

    Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 m

    НизкаяCVSS 2,0Эксплойта нетEPSS 0 %

    12 февр. 2025 г.

  • GHSA-qc59-cxj2-c2w4
    8Наблюдать

    aws-cdk-lib's aspect order change causes different Permissions Boundary assigned to Role

    НизкаяCVSS 2,2Эксплойта нет

    npm · aws-cdk-lib15 апр. 2025 г.

Все классы уязвимостей