CWE-277 · 66 kayıt
Insecure Inherited Permissions
Bu sınıftaki CVE’ler
66 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-36539Kavram kanıtı | Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account'sprojectcontour · contour · CWE-277 | Kritik9,8 | — | %1,3 | 24 Tem 2024 |
39İzleyin | CVE-2024-36540İstismar yok | Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service external-secrets · external secrets operator · CWE-277 | Kritik9,8 | — | %0,4 | 24 Tem 2024 |
36İzleyin | CVE-2023-27842Kavram kanıtı | Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code viaextplorer · extplorer · CWE-277 | Yüksek8,8 | — | %2,4 | 21 Mar 2023 |
35İzleyin | CVE-2024-36542İstismar yok | Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tokCWE-277 | Yüksek8,8 | — | %0,5 | 25 Tem 2024 |
35İzleyin | CVE-2024-6605İstismar yok | Firefox Android missed activation delay to prevent tapjackingmozilla · firefox · CWE-277 | Yüksek8,8 | — | %0,4 | 9 Tem 2024 |
33İzleyin | CVE-2024-7143İstismar yok | Pulpcore: rbac permissions incorrectly assigned in tasks that create objectspulpproject · pulp · CWE-277 | Yüksek8,3 | — | %0,6 | 7 Ağu 2024 |
33İzleyin | CVE-2024-34329Kavram kanıtı | Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticatedCWE-277 | Yüksek8,4 | — | %0,6 | 22 Tem 2024 |
33İzleyin | CVE-2024-29417İstismar yok | Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password resCWE-277 | Yüksek8,4 | — | %0,2 | 3 May 2024 |
32İzleyin | CVE-2025-58437İstismar yok | Coder's privilege escalation vulnerability could lead to a cross workspace compromisecoder · coder · CWE-277 | Yüksek8,1 | — | %0,4 | 5 Eyl 2025 |
31İzleyin | CVE-2024-27822Silahlaştırılmış | A logic issue was addressed with improved restrictions.apple · macos · CWE-277 | Yüksek7,8 | — | %1,5 | 14 May 2024 |
31İzleyin | CVE-2020-5343İstismar yok | Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissdell · os recovery image for microsoft windows 10 · CWE-277 | Yüksek7,8 | — | %0,3 | 4 May 2020 |
31İzleyin | CVE-2024-23233İstismar yok | This issue was addressed with improved checks.apple · macos · CWE-277 | Yüksek7,8 | — | %0,2 | 7 Mar 2024 |
31İzleyin | CVE-2023-34314İstismar yok | Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentiallintel · simics simulator · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Kas 2023 |
31İzleyin | CVE-2023-39230İstismar yok | Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user intel · rapid storage technology · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Kas 2023 |
31İzleyin | CVE-2023-34997İstismar yok | Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authintel · server configuration utility · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Kas 2023 |
31İzleyin | CVE-2023-45736İstismar yok | Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enaintel · power gadget · CWE-277 | Yüksek7,8 | — | %0,2 | 16 May 2024 |
31İzleyin | CVE-2026-30266İstismar yok | Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a crafdeepcool · deepcreative · CWE-277 | Yüksek7,8 | — | %0,2 | 20 Nis 2026 |
31İzleyin | CVE-2022-33898İstismar yok | Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated intel · nuc watchdog timer utility · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Kas 2023 |
31İzleyin | CVE-2023-33870İstismar yok | Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enintel · administrative tools for intel network adapters · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Şub 2024 |
31İzleyin | CVE-2022-41700İstismar yok | Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatintel · nuc pro software suite · CWE-277 | Yüksek7,8 | — | %0,2 | 14 Kas 2023 |
31İzleyin | CVE-2024-21835İstismar yok | Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable intel · extreme tuning utility · CWE-277 | Yüksek7,8 | — | %0,2 | 16 May 2024 |
31İzleyin | CVE-2022-46656İstismar yok | Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentiallyintel · nuc pro software suite · CWE-277 | Yüksek7,8 | — | %0,1 | 10 May 2023 |
31İzleyin | CVE-2022-38103İstismar yok | Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated useintel · nuc software studio service · CWE-277 | Yüksek7,8 | — | %0,1 | 10 May 2023 |
31İzleyin | CVE-2022-41687İstismar yok | Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4intel · nuc p14e laptop element · CWE-277 | Yüksek7,8 | — | %0,1 | 10 May 2023 |
31İzleyin | CVE-2022-41658İstismar yok | Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentiaintel · vtune profiler · CWE-277 | Yüksek7,8 | — | %0,1 | 10 May 2023 |
- CVE-2024-3653939İzleyin
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
KritikCVSS 9,8Kavram kanıtıEPSS %1projectcontour · contour24 Tem 2024
- CVE-2024-3654039İzleyin
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service
KritikCVSS 9,8İstismar yokEPSS %0external-secrets · external secrets operator24 Tem 2024
- CVE-2023-2784236İzleyin
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via
YüksekCVSS 8,8Kavram kanıtıEPSS %2extplorer · extplorer21 Mar 2023
- CVE-2024-3654235İzleyin
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tok
YüksekCVSS 8,8İstismar yokEPSS %025 Tem 2024
- CVE-2024-660535İzleyin
Firefox Android missed activation delay to prevent tapjacking
YüksekCVSS 8,8İstismar yokEPSS %0mozilla · firefox9 Tem 2024
- CVE-2024-714333İzleyin
Pulpcore: rbac permissions incorrectly assigned in tasks that create objects
YüksekCVSS 8,3İstismar yokEPSS %1pulpproject · pulp7 Ağu 2024
- CVE-2024-3432933İzleyin
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated
YüksekCVSS 8,4Kavram kanıtıEPSS %122 Tem 2024
- CVE-2024-2941733İzleyin
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password res
YüksekCVSS 8,4İstismar yokEPSS %03 May 2024
- CVE-2025-5843732İzleyin
Coder's privilege escalation vulnerability could lead to a cross workspace compromise
YüksekCVSS 8,1İstismar yokEPSS %0coder · coder5 Eyl 2025
- CVE-2024-2782231İzleyin
A logic issue was addressed with improved restrictions.
YüksekCVSS 7,8SilahlaştırılmışEPSS %1apple · macos14 May 2024
- CVE-2020-534331İzleyin
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permiss
YüksekCVSS 7,8İstismar yokEPSS %0dell · os recovery image for microsoft windows 104 May 2020
- CVE-2024-2323331İzleyin
This issue was addressed with improved checks.
YüksekCVSS 7,8İstismar yokEPSS %0apple · macos7 Mar 2024
- CVE-2023-3431431İzleyin
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentiall
YüksekCVSS 7,8İstismar yokEPSS %0intel · simics simulator14 Kas 2023
- CVE-2023-3923031İzleyin
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user
YüksekCVSS 7,8İstismar yokEPSS %0intel · rapid storage technology14 Kas 2023
- CVE-2023-3499731İzleyin
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an auth
YüksekCVSS 7,8İstismar yokEPSS %0intel · server configuration utility14 Kas 2023
- CVE-2023-4573631İzleyin
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially ena
YüksekCVSS 7,8İstismar yokEPSS %0intel · power gadget16 May 2024
- CVE-2026-3026631İzleyin
Insecure Permissions vulnerability in DeepCool DeepCreative v.1.2.12 and before allows a local attacker to execute arbitrary code via a craf
YüksekCVSS 7,8İstismar yokEPSS %0deepcool · deepcreative20 Nis 2026
- CVE-2022-3389831İzleyin
Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated
YüksekCVSS 7,8İstismar yokEPSS %0intel · nuc watchdog timer utility14 Kas 2023
- CVE-2023-3387031İzleyin
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially en
YüksekCVSS 7,8İstismar yokEPSS %0intel · administrative tools for intel network adapters14 Şub 2024
- CVE-2022-4170031İzleyin
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticat
YüksekCVSS 7,8İstismar yokEPSS %0intel · nuc pro software suite14 Kas 2023
- CVE-2024-2183531İzleyin
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable
YüksekCVSS 7,8İstismar yokEPSS %0intel · extreme tuning utility16 May 2024
- CVE-2022-4665631İzleyin
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially
YüksekCVSS 7,8İstismar yokEPSS %0intel · nuc pro software suite10 May 2023
- CVE-2022-3810331İzleyin
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated use
YüksekCVSS 7,8İstismar yokEPSS %0intel · nuc software studio service10 May 2023
- CVE-2022-4168731İzleyin
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4
YüksekCVSS 7,8İstismar yokEPSS %0intel · nuc p14e laptop element10 May 2023
- CVE-2022-4165831İzleyin
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentia
YüksekCVSS 7,8İstismar yokEPSS %0intel · vtune profiler10 May 2023