Skip to main content

CWE archive

CWE-732 CVEs

Programmatic archive

1,712 CVEs tagged with CWE-732143 Critical, 842 High, 630 Medium, 97 Low, 0 Unrated.

CVE-2024-45841

Published Dec 5, 2024

Incorrect permission assignment for critical resource issue exists in UD-LT1 firmware Ver.2.1.9 and earlier and UD-LT1/EX firmware Ver.2.1.9 and earlier. If an attacker with the g…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2024-12151

Published Dec 4, 2024

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12149

Published Dec 4, 2024

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that r…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37574

Published Dec 4, 2024

The GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls without user interaction by sending a cra…

CVSS 8.2 · High

CVE-2024-42449

Published Dec 4, 2024

From the VSPC management agent machine, under condition that the management agent is authorized on the server, it is possible to remove arbitrary files on the VSPC server machine.

CVSS 7.1 · High
evidence mentions
6
Buzz score
34.0

CVE-2024-54159

Published Nov 29, 2024

stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack.

CVSS 4.1 · Medium

CVE-2024-28955

Published Nov 26, 2024

Affected devices create coredump files when crashed, storing them with world-readable permission. Any local user of the device can examine the coredump files, and research the mem…

CVSS 5.9 · Medium

CVE-2024-9245

Published Nov 22, 2024

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9244

Published Nov 22, 2024

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affec…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7245

Published Nov 22, 2024

Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected inst…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-6871

Published Nov 22, 2024

G DATA Total Security Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected instal…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38646

Published Nov 22, 2024

An incorrect permission assignment for critical resource vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow local authenticated…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11176

Published Nov 20, 2024

Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective per…

CVSS 5.3 · Medium

CVE-2024-41974

Published Nov 18, 2024

A low privileged remote attacker may modify the BACNet service properties due to incorrect permission assignment for critical resources which may lead to a DoS limited to BACNet c…

CVSS 7.1 · High

CVE-2024-41970

Published Nov 18, 2024

A low privileged remote attacker may gain access to forbidden diagnostic data due to incorrect permission assignment for critical resources.

CVSS 5.7 · Medium

CVE-2024-36294

Published Nov 13, 2024

Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local acce…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36276

Published Nov 13, 2024

Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local acce…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47808

Published Nov 12, 2024

A vulnerability has been identified in SINEC NMS (All versions < V3.0 SP1). The affected application contains a database function, that does not properly restrict the permissions…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47783

Published Nov 12, 2024

A vulnerability has been identified in SIPORT (All versions < V3.4.0). The affected application improperly assigns file permissions to installation folders. This could allow a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50590

Published Nov 8, 2024

Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries…

CVSS 7.8 · High

CVE-2024-10526

Published Nov 7, 2024

Rapid7 Velociraptor MSI Installer versions below 0.73.3 suffer from a vulnerability whereby it creates the installation directory with WRITE_DACL permission to the BUILTIN\\Users…

CVSS 8.6 · High
Showing 376-400 of 1,712 CVEsPage 16 of 69