CWE-732 · 1 473 записей
Incorrect Permission Assignment for Critical Resource
CVE этого класса
1 476 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
76На этой неделе | CVE-2019-15752Готовый эксплойт | Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.exdocker · docker · CWE-732 | Высокая7,8 | KEV | 48,6 % | 28 авг. 2019 г. |
72На этой неделе | CVE-2022-22960Готовый эксплойт | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissiovmware · cloud foundation · CWE-732 | Высокая7,8 | KEV | 35,5 % | 13 апр. 2022 г. |
66На этой неделе | CVE-2011-3923Готовый эксплойт | Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary apache · struts · CWE-732 | Критическая9,8 | — | 89,5 % | 1 нояб. 2019 г. |
58В плане | CVE-2018-13374Готовый эксплойт | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtfortinet · fortiadc · CWE-732 | Средняя4,3 | KEV | 37,8 % | 22 янв. 2019 г. |
53В плане | CVE-2023-32986Эксплойта нет | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File jenkins · file parameters · CWE-732 | Высокая8,8 | — | 60,7 % | 16 мая 2023 г. |
49В плане | CVE-2017-16885Proof of concept | Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Usfiberhome · lm53q1 firmware · CWE-732 | Критическая9,8 | — | 33,5 % | 12 янв. 2018 г. |
47В плане | CVE-2018-1000207Эксплойта нет | MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phptmodx · modx revolution · CWE-732 | Высокая7,2 | — | 64,1 % | 13 июл. 2018 г. |
43В плане | CVE-2018-4072Эксплойта нет | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | Высокая8,8 | — | 26,4 % | 6 мая 2019 г. |
43В плане | CVE-2018-4073Эксплойта нет | An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLinksierrawireless · airlink es450 firmware · CWE-732 | Высокая8,8 | — | 25,6 % | 6 мая 2019 г. |
43В плане | CVE-2018-10285Proof of concept | The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.ericssonlg · ipecs nms · CWE-732 | Критическая9,8 | — | 12,8 % | 22 апр. 2018 г. |
43В плане | CVE-2018-1000226Proof of concept | Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older versioncobblerd · cobbler · CWE-732 | Критическая9,8 | — | 12,6 % | 20 авг. 2018 г. |
42В плане | CVE-2020-11107Proof of concept | An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.apachefriends · xampp · CWE-732 | Высокая8,8 | — | 22,5 % | 2 апр. 2020 г. |
42В плане | CVE-2022-43773Эксплойта нет | Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resourcehitachi · vantara pentaho business analytics server · CWE-732 | Высокая8,8 | — | 22,2 % | 3 апр. 2023 г. |
42В плане | CVE-2017-9462Готовый эксплойт | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbimercurial · mercurial · CWE-732 | Высокая8,8 | — | 21,7 % | 6 июн. 2017 г. |
42В плане | CVE-2026-21902Proof of concept | Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as rootjuniper · junos os evolved · CWE-732 | Критическая9,3 | — | 18,0 % | 25 февр. 2026 г. |
41В плане | CVE-2018-14916Proof of concept | LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.loytec · lgate-902 firmware · CWE-732 | Критическая9,1 | — | 17,2 % | 28 июн. 2019 г. |
41В плане | CVE-2017-8857Эксплойта нет | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote commanveritas · netbackup · CWE-732 | Критическая9,8 | — | 5,7 % | 9 мая 2017 г. |
40В плане | CVE-2019-7958Эксплойта нет | Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.adobe · creative cloud · CWE-732 | Критическая9,8 | — | 4,4 % | 16 авг. 2019 г. |
40В плане | CVE-2017-9602Proof of concept | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.kbvault mysql project · kbvault mysql · CWE-732 | Критическая9,8 | — | 4,3 % | 16 июн. 2017 г. |
40В плане | CVE-2019-8256Эксплойта нет | ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.adobe · coldfusion · CWE-732 | Критическая9,8 | — | 4,0 % | 19 дек. 2019 г. |
40В плане | CVE-2020-9671Эксплойта нет | Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.adobe · creative cloud desktop application · CWE-732 | Критическая9,8 | — | 4,0 % | 16 июл. 2020 г. |
40В плане | CVE-2020-28910Эксплойта нет | Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of snagios · nagios xi · CWE-732 | Критическая9,8 | — | 3,9 % | 24 мая 2021 г. |
40В плане | CVE-2018-10381Эксплойта нет | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.mcafee · tunnelbear · CWE-732 | Критическая9,8 | — | 3,8 % | 25 апр. 2018 г. |
40В плане | CVE-2017-8856Эксплойта нет | In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution uveritas · netbackup · CWE-732 | Критическая9,8 | — | 3,8 % | 9 мая 2017 г. |
40В плане | CVE-2017-6950Эксплойта нет | SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAsap · gui for windows · CWE-732 | Критическая9,8 | — | 3,8 % | 23 мар. 2017 г. |
- CVE-2019-1575276На этой неделе
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-credential-wincred.ex
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 49 %docker · docker28 авг. 2019 г.
- CVE-2022-2296072На этой неделе
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissio
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 36 %vmware · cloud foundation13 апр. 2022 г.
- CVE-2011-392366На этой неделе
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary
КритическаяCVSS 9,8Готовый эксплойтEPSS 89 %apache · struts1 нояб. 2019 г.
- CVE-2018-1337458В плане
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obt
СредняяCVSS 4,3KEVГотовый эксплойтEPSS 38 %fortinet · fortiadc22 янв. 2019 г.
- CVE-2023-3298653В плане
Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File
ВысокаяCVSS 8,8Эксплойта нетEPSS 61 %jenkins · file parameters16 мая 2023 г.
- CVE-2017-1688549В плане
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet Us
КритическаяCVSS 9,8Proof of conceptEPSS 33 %fiberhome · lm53q1 firmware12 янв. 2018 г.
- CVE-2018-100020747В плане
MODX Revolution version <=2.6.4 contains a Incorrect Access Control vulnerability in Filtering user parameters before passing them into phpt
ВысокаяCVSS 7,2Эксплойта нетEPSS 64 %modx · modx revolution13 июл. 2018 г.
- CVE-2018-407243В плане
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %sierrawireless · airlink es450 firmware6 мая 2019 г.
- CVE-2018-407343В плане
An exploitable Permission Assignment vulnerability exists in the ACEManager EmbeddedAceSet_Task.cgi functionality of Sierra Wireless AirLink
ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %sierrawireless · airlink es450 firmware6 мая 2019 г.
- CVE-2018-1028543В плане
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms.
КритическаяCVSS 9,8Proof of conceptEPSS 13 %ericssonlg · ipecs nms22 апр. 2018 г.
- CVE-2018-100022643В плане
Cobbler version Verified as present in Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ or possibly even older version
КритическаяCVSS 9,8Proof of conceptEPSS 13 %cobblerd · cobbler20 авг. 2018 г.
- CVE-2020-1110742В плане
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.
ВысокаяCVSS 8,8Proof of conceptEPSS 22 %apachefriends · xampp2 апр. 2020 г.
- CVE-2022-4377342В плане
Hitachi Vantara Pentaho Business Analytics Server - Incorrect Permission Assignment for Critical Resource
ВысокаяCVSS 8,8Эксплойта нетEPSS 22 %hitachi · vantara pentaho business analytics server3 апр. 2023 г.
- CVE-2017-946242В плане
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbi
ВысокаяCVSS 8,8Готовый эксплойтEPSS 22 %mercurial · mercurial6 июн. 2017 г.
- CVE-2026-2190242В плане
Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
КритическаяCVSS 9,3Proof of conceptEPSS 18 %juniper · junos os evolved25 февр. 2026 г.
- CVE-2018-1491641В плане
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
КритическаяCVSS 9,1Proof of conceptEPSS 17 %loytec · lgate-902 firmware28 июн. 2019 г.
- CVE-2017-885741В плане
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated file copy and arbitrary remote comman
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %veritas · netbackup9 мая 2017 г.
- CVE-2019-795840В плане
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · creative cloud16 авг. 2019 г.
- CVE-2017-960240В плане
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-management component.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %kbvault mysql project · kbvault mysql16 июн. 2017 г.
- CVE-2019-825640В плане
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · coldfusion19 дек. 2019 г.
- CVE-2020-967140В плане
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %adobe · creative cloud desktop application16 июл. 2020 г.
- CVE-2020-2891040В плане
Creation of a Temporary Directory with Insecure Permissions in Nagios XI 5.7.5 and earlier allows for Privilege Escalation via creation of s
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %nagios · nagios xi24 мая 2021 г.
- CVE-2018-1038140В плане
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mcafee · tunnelbear25 апр. 2018 г.
- CVE-2017-885640В плане
In Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and earlier, there is unauthenticated, arbitrary remote command execution u
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %veritas · netbackup9 мая 2017 г.
- CVE-2017-695040В плане
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABA
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sap · gui for windows23 мар. 2017 г.