Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,704 CVEs tagged with CWE-732142 Critical, 839 High, 625 Medium, 96 Low, 2 Unrated.

CVE-2024-55411

Published Jan 7, 2025

An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.

CVSS 8.8 · High

CVE-2024-53932

Published Jan 6, 2025

The com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enables any application (with no permissions)…

CVSS 9.1 · Critical

CVE-2024-53931

Published Jan 6, 2025

The com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permissions) to place phone calls without u…

CVSS 9.1 · Critical

CVE-2024-47475

Published Jan 6, 2025

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially e…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-49385

Published Jan 2, 2025

Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736, Acronis True Image OEM (…

CVSS 5.5 · Medium

CVE-2024-45497

Published Dec 31, 2024

A flaw was found in the OpenShift build process, where the docker-build container is configured with a hostPath volume mount that maps the node's /var/lib/kubelet/config.json file…

CVSS 7.6 · High
evidence mentions
9
Buzz score
33.0

CVE-2024-38864

Published Dec 19, 2024

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47104

Published Dec 18, 2024

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file securi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12564

Published Dec 12, 2024

Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default set…

CVSS 6.9 · Medium

CVE-2024-12363

Published Dec 11, 2024

Insufficient permissions in the TeamViewer Patch & Asset Management component prior to version 24.12 on Windows allows a local authenticated user to delete arbitrary files. TeamVi…

CVSS 7.1 · High

CVE-2024-8540

Published Dec 10, 2024

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8256

Published Dec 10, 2024

In Teltonika Networks RUTOS devices, running on versions 7.0 to 7.8 (excluding) and TSWOS devices running on versions 1.0 to 1.3 (excluding), due to incorrect permission handling…

CVSS 5.9 · Medium

CVE-2024-41647

Published Dec 6, 2024

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the n…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45841

Published Dec 5, 2024

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the g…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-12151

Published Dec 4, 2024

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12149

Published Dec 4, 2024

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that r…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37574

Published Dec 4, 2024

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a cra…

CVSS 8.2 · High

CVE-2024-42449

Published Dec 4, 2024

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.0

CVE-2024-54159

Published Nov 29, 2024

stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.

CVSS 4.1 · Medium
Showing 351-375 of 1,704 CVEsPage 15 of 69