CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2021-3418 MEDIUM
GRUB2 < 2.06 - Secure Boot Bypass via Shim Lock Mechanism
CVSS 6.4
CVE-2021-21379 HIGH
XWiki Platform 11.4-11.10.10 - Improper Preservation of Permissions in wikimacrocontent
CVSS 7.7
CVE-2021-20263 LOW
QEMU virtio-fs - Privilege Escalation
CVSS 3.3
CVE-2021-23963 MEDIUM
Firefox < 85.0 - Permission State Reset via WebRTC Geolocation Sharing
CVSS 4.3
CVE-2020-36070 CRITICAL
Voyager <=1.4 - Code Execution via PHP File Upload to Media Component
CVSS 9.8
CVE-2020-18329 HIGH
Rehau pCOWeb <6.27 - Info Disclosure
CVSS 7.5
CVE-2020-12744 HIGH
Verint Desktop Resources 15.2 - Privilege Escalation
CVSS 7.8
CVE-2020-15496 HIGH
Acronis True Image for Mac < 2021 Update 4 - Local Privilege Escalation via Insecure Folder Permissions
CVSS 7.8
CVE-2020-27383 HIGH
Battle.Net 1.27.1.12428 - Privilege Escalation
CVSS 7.8
CVE-2020-18890 CRITICAL
puppyCMS 5.1 - Remote Code Execution via Insecure Permissions in /admin/functions.php
CVSS 9.8
CVE-2020-26246 HIGH
Pimcore <6.8.5 - Privilege Escalation
CVSS 7.7
CVE-2020-5796 HIGH
Nagios XI <5.7.4 - Privilege Escalation
CVSS 7.8
CVE-2020-12353 MEDIUM
Intel Data Center Manager < 3.6.2 - Authenticated Denial of Service via Network Access
CVSS 6.5
CVE-2020-12345 HIGH
Intel(R) Data Center Manager Console <3.6.2 - Privilege Escalation
CVSS 7.8
CVE-2020-12335 HIGH
Intel(R) Processor Identification Utility <6.4.0603 - Privilege Esc...
CVSS 7.8
CVE-2020-12334 HIGH
Intel(R) Advisor <2020 Update 2 - Privilege Escalation
CVSS 7.8
CVE-2020-12332 HIGH
Intel(R) HID Event Filter Driver - Privilege Escalation
CVSS 7.8
CVE-2020-12330 HIGH
Intel(R) Falcon 8+ UAS AscTec Thermal Viewer - Privilege Escalation
CVSS 7.8
CVE-2020-16910 MEDIUM
Microsoft Windows - Privilege Escalation
CVSS 6.2
CVE-2020-8182 HIGH
Nextcloud Deck 0.8.0 - Privilege Escalation
CVSS 8.0
CVE-2020-6564 MEDIUM
Google Chrome <85.0.4183.83 - Info Disclosure
CVSS 6.5
CVE-2020-0405 HIGH
Android 11 - Local Privilege Escalation via Unsafe Implicit PendingIntent
CVSS 7.8
CVE-2020-13308 LOW
GitLab <13.1.10-13.3.4 - Info Disclosure
CVSS 2.7
CVE-2020-13282 LOW
GitLab <13.0.12-13.2.3 - Privilege Escalation
CVSS 3.1
CVE-2020-8913 HIGH
Android Play Core Library < 1.7.2 - Local Arbitrary Code Execution via SplitCompat.install Endpoint
CVSS 8.8
Details
Vulnerabilities 337