VYPR

CWE-277

Insecure Inherited Permissions

VariantDraft

Description

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (74)

page 4 of 4
  • CVE-2024-27847MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to bypass Privacy preferences.

  • CVE-2024-27834MedMay 14, 2024
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.

  • CVE-2021-24031MedMar 4, 2021
    risk 0.36cvss 5.5epss 0.00

    In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writable to unintended parties.

  • CVE-2021-24032MedMar 4, 2021
    risk 0.31cvss 4.7epss 0.00

    Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files could therefore momentarily be readable or…

  • CVE-2025-65111MedNov 21, 2025
    risk 0.27cvss 5.3epss 0.00

    SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema includes the following characteristics: permission defined in terms of a union (+) and that union references the same relation on…

  • CVE-2023-29065MedNov 28, 2023
    risk 0.27cvss 4.1epss 0.00

    The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.

  • CVE-2018-25111MedMay 31, 2025
    risk 0.26cvss 5.1epss 0.00

    django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.

  • CVE-2024-45599LowSep 25, 2024
    risk 0.25cvss 3.8epss 0.00

    Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone without explicitly being granted access,…

  • CVE-2026-44997MedMay 11, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenClaw before 2026.4.22 contains a security envelope constraint bypass vulnerability allowing restricted subagents to spawn ACP child sessions that fail to inherit depth, child-count limits, control scope, or target-agent restrictions. Attackers can exploit this by spawning…

  • CVE-2025-9039MedAug 14, 2025
    risk 0.21cvss 4.3epss 0.00

    We identified an issue in the Amazon ECS agent where, under certain conditions, an introspection server could be accessed off-host by another instance if the instances are in the same security group or if their security groups allow incoming connections that include the port…

  • CVE-2026-9046HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

  • CVE-2025-32797HigJun 16, 2025
    risk 0.00cvss 7.0epss 0.00

    Conda-build contains commands and tools to build conda packages. Prior to version 25.3.1, the write_build_scripts function in conda-build creates the temporary build script conda_build.sh with overly permissive file permissions (0o766), allowing write access to all users.…

  • CVE-2021-32725LowJul 12, 2021
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3.…

  • CVE-2019-5068MedNov 5, 2019
    risk 0.00cvss 4.4epss 0.00

    An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.