CWE-732
Incorrect Permission Assignment for Critical Resource
Description
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-122 · CAPEC-127 · CAPEC-17 · CAPEC-180 · CAPEC-206 · CAPEC-234 · CAPEC-60 · CAPEC-61 · CAPEC-62 · CAPEC-642
CVEs mapped to this weakness (1,787)
page 83 of 90| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-19086 | Med | 0.21 | 4.3 | 0.01 | Jan 3, 2020 | Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2). | ||
| CVE-2012-6655 | Low | 0.21 | 3.3 | 0.00 | Nov 27, 2019 | An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords. | ||
| CVE-2019-13679 | Low | 0.21 | 3.3 | 0.01 | Nov 25, 2019 | Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file. | ||
| CVE-2019-15340 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006)… | ||
| CVE-2019-15339 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the… | ||
| CVE-2019-15338 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app… | ||
| CVE-2019-15337 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device… | ||
| CVE-2019-15336 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app… | ||
| CVE-2019-15335 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device… | ||
| CVE-2019-15334 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app… | ||
| CVE-2019-15333 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2019 | The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the… | ||
| CVE-2019-5642 | Low | 0.21 | 3.3 | 0.00 | Nov 6, 2019 | Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is… | ||
| CVE-2016-4983 | Low | 0.21 | 3.3 | 0.00 | Nov 5, 2019 | A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files. | ||
| CVE-2019-11806 | Low | 0.21 | 3.3 | 0.00 | Aug 20, 2019 | OX App Suite 7.10.1 and earlier has Insecure Permissions. | ||
| CVE-2018-20936 | Low | 0.21 | 3.3 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | ||
| CVE-2019-14395 | Low | 0.21 | 3.3 | 0.00 | Jul 30, 2019 | cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). | ||
| CVE-2018-12209 | Low | 0.21 | 3.3 | 0.00 | Mar 14, 2019 | Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an… | ||
| CVE-2019-7729 | Low | 0.21 | 3.3 | 0.00 | Feb 22, 2019 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not… | ||
| CVE-2012-0433 | Low | 0.21 | 3.3 | 0.00 | Jun 8, 2018 | The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data. | ||
| CVE-2017-1699 | Low | 0.21 | 3.3 | 0.00 | Jan 4, 2018 | IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391. |
- risk 0.21cvss 4.3epss 0.01
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
- risk 0.21cvss 3.3epss 0.00
An issue exists AccountService 0.6.37 in the user_change_password_authorized_cb() function in user.c which could let a local users obtain encrypted passwords.
- risk 0.21cvss 3.3epss 0.01
Insufficient policy enforcement in PDFium in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to show print dialogs via a crafted PDF file.
- risk 0.21cvss 3.3epss 0.00
The Xiaomi Redmi 6 Pro Android device with a build fingerprint of xiaomi/sakura_india/sakura_india:8.1.0/OPM1.171019.019/V9.6.4.0.ODMMIFD:user/release-keys contains a pre-installed app with a package name of com.huaqin.factory app (versionCode=1, versionName=QL1715_201805292006)…
- risk 0.21cvss 3.3epss 0.00
The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…
- risk 0.21cvss 3.3epss 0.00
The Lava Iris 88 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…
- risk 0.21cvss 3.3epss 0.00
The Lava Z81 Android device with a build fingerprint of LAVA/Z81/Z81:8.1.0/O11019/1532317309:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device…
- risk 0.21cvss 3.3epss 0.00
The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app…
- risk 0.21cvss 3.3epss 0.00
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device…
- risk 0.21cvss 3.3epss 0.00
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app…
- risk 0.21cvss 3.3epss 0.00
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the…
- risk 0.21cvss 3.3epss 0.00
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is…
- risk 0.21cvss 3.3epss 0.00
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.
- risk 0.21cvss 3.3epss 0.00
OX App Suite 7.10.1 and earlier has Insecure Permissions.
- risk 0.21cvss 3.3epss 0.00
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
- risk 0.21cvss 3.3epss 0.00
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
- risk 0.21cvss 3.3epss 0.00
Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an…
- risk 0.21cvss 3.3epss 0.00
An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not…
- risk 0.21cvss 3.3epss 0.00
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allowing local users to read confidential data.
- risk 0.21cvss 3.3epss 0.00
IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.