VYPR

CWE-281

Improper Preservation of Permissions

BaseDraft

Description

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (352)

page 8 of 18
  • CVE-2020-8190HigJul 10, 2020
    risk 0.49cvss 7.5epss 0.01

    Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.

  • CVE-2019-20846HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 5.18.0. It has weak permissions for server-local file storage.

  • CVE-2019-20843HigJun 19, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Mattermost Server before 5.18.0, 5.17.2, 5.16.4, 5.15.4, and 5.9.7. There are weak permissions for configuration files.

  • CVE-2020-13763HigJun 2, 2020
    risk 0.49cvss 7.5epss 0.01

    In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.

  • CVE-2005-1920HigJul 26, 2005
    risk 0.49cvss 7.5epss 0.04

    The (1) Kate and (2) Kwrite applications in KDE KDE 3.2.x through 3.4.0 do not properly set the same permissions on the backup file as were set on the original file, which could allow local users and possibly remote attackers to obtain sensitive information.

  • CVE-2002-2323HigDec 31, 2002
    risk 0.49cvss 7.5epss 0.02

    Sun PC NetLink 1.0 through 1.2 does not properly set the access control list (ACL) for files and directories that use symbolic links and have been restored from backup, which could allow local or remote attackers to bypass intended access restrictions.

  • CVE-2001-1515HigDec 31, 2001
    risk 0.49cvss 7.5epss 0.04

    Macintosh clients, when using NT file system volumes on Windows 2000 SP1, create subdirectories and automatically modify the inherited NTFS permissions, which may cause the directories to have less restrictive permissions than intended.

  • CVE-2025-24337HigJan 20, 2025
    risk 0.48cvss 8.4epss 0.00

    WriteFreely through 0.15.1, when MySQL is used, allows local users to discover credentials by reading config.ini.

  • CVE-2019-13668HigNov 25, 2019
    risk 0.48cvss 7.4epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2017-8494HigJun 15, 2017
    risk 0.48cvss 7.3epss 0.02

    Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a locally-authenticated attacker to run a specially crafted application on a targeted system when Windows Secure Kernel Mode fails to properly handle objects in memory, aka "Windows Elevation of…

  • CVE-2024-23464HigAug 6, 2024
    risk 0.47cvss 7.2epss 0.00

    In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1

  • CVE-2026-35341HigApr 22, 2026
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in uutils coreutils mkfifo allows for the unauthorized modification of permissions on existing files. When mkfifo fails to create a FIFO because a file already exists at the target path, it fails to terminate the operation for that path and continues to execute a…

  • CVE-2025-37735HigNov 6, 2025
    risk 0.46cvss 7.0epss 0.00

    Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being deleted by the Defend service running as SYSTEM. In some cases, this could result in local privilege escalation.

  • CVE-2024-40821HigJul 29, 2024
    risk 0.46cvss 7.1epss 0.00

    An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.

  • CVE-2024-40805HigJul 29, 2024
    risk 0.46cvss 7.1epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.

  • CVE-2023-25646HigJun 20, 2024
    risk 0.46cvss 7.1epss 0.00

    There is an unauthorized access vulnerability in ZTE H388X. If H388X is caused by brute-force serial port cracking,attackers with common user permissions can use this vulnerability to obtain elevated permissions on the affected device by performing specific operations.

  • CVE-2024-28746HigMar 14, 2024
    risk 0.46cvss 8.1epss 0.01

    Apache Airflow, versions 2.8.0 through 2.8.2, has a vulnerability that allows an authenticated user with limited permissions to access resources such as variables, connections, etc from the UI which they do not have permission to access.  Users of Apache Airflow are…

  • CVE-2023-39902HigOct 17, 2023
    risk 0.46cvss 7.0epss 0.00

    A software vulnerability has been identified in the U-Boot Secondary Program Loader (SPL) before 2023.07 on select NXP i.MX 8M family processors. Under certain conditions, a crafted Flattened Image Tree (FIT) format structure can be used to overwrite SPL memory, allowing…

  • CVE-2023-31926HigAug 2, 2023
    risk 0.46cvss 7.1epss 0.00

    System files could be overwritten using the less command in Brocade Fabric OS before Brocade Fabric OS v9.1.1c and v9.2.0.

  • CVE-2017-8593HigAug 8, 2017
    risk 0.46cvss 7.0epss 0.01

    Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle…