CWE-277

Insecure Inherited Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

A product defines a set of insecure permissions that are inherited by objects that are created by the program.

70 vulnerabilities with CWE-277
CVE-2023-34997 MEDIUM
Intel Server Configuration Utility < 16.0.9 - Authenticated Privilege Escalation via Insecure Inherited Permissions
CVSS 6.7
CVE-2023-34314 MEDIUM
Intel Simics Simulator < 1.7.2 - Authenticated Privilege Escalation via Insecure Inherited Permissions
CVSS 6.7
CVE-2023-34391 HIGH
SEL-5033 AcSELerator RTAC Software < 1.35.151.21000 - Insecure Inherited Permissions
CVSS 7.4
CVE-2023-28658 MEDIUM
Intel oneMKL <2022.0 - Privilege Escalation
CVSS 6.7
CVE-2023-33990 HIGH
SAP SQL Anywhere 17.0 - Denial of Service via Shared Memory Object Manipulation
CVSS 7.8
CVE-2023-27842 HIGH
eXtplorer 2.1.15 - Remote Code Execution via Insecure Permissions in index.php
CVSS 8.8
CVE-2022-41700 MEDIUM
Intel(R) NUC Pro Software Suite <2.0.0.9 - Privilege Escalation
CVSS 6.7
CVE-2022-33898 MEDIUM
Intel(R) NUC Watchdog Timer <2.0.21.0 - Privilege Escalation
CVSS 6.7
CVE-2022-46656 MEDIUM
Intel(R) NUC Pro Software Suite <2.0.0.3 - Privilege Escalation
CVSS 6.7
CVE-2022-41687 MEDIUM
Intel(R) NUC P14E Laptop Element <1.1.44 - Privilege Escalation
CVSS 6.7
CVE-2022-41658 MEDIUM
Intel VTune <2023.0 - Privilege Escalation
CVSS 6.7
CVE-2022-38103 MEDIUM
Intel(R) NUC Software Studio Service <1.17.38.0 - Privilege Escalation
CVSS 6.7
CVE-2022-36377 MEDIUM
Intel(R) Wireless Adapter Driver <22.190.0.3 - Privilege Escalation
CVSS 6.7
CVE-2021-41170 CRITICAL
neoan3-apps/template <1.1.1 - Code Injection
CVSS 9.8
CVE-2021-32725 LOW
Nextcloud Server <19.0.13, <20.011, <21.0.3 - Info Disclosure
CVSS 3.5
CVE-2021-24032 MEDIUM
Zstandard 1.4.1-1.4.8 - Insecure Inherited Permissions via Output File Creation
CVSS 4.7
CVE-2021-24031 MEDIUM
Zstandard < 1.4.1 - Insecure Inherited Permissions
CVSS 5.5
CVE-2020-5343 HIGH
Dell OS Recovery Image for Windows 10 < 2019-12-20 - Unauthorized Access via Insecure Permissions
CVSS 7.3
CVE-2019-5068 MEDIUM
X11 Mesa 3D Graphics Library <19.1.2 - Memory Corruption
CVSS 4.4
CVE-2018-25111 MEDIUM
django-helpdesk <1.0.0 - Info Disclosure
CVSS 5.1
Details
Vulnerabilities 70