CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2019-14226 HIGH
OX App Suite <7.10.2 - Info Disclosure
CVSS 8.1
CVE-2019-0073 MEDIUM
Junos OS Insecure PKI Key Export Permissions
CVSS 6.6
CVE-2019-14956 MEDIUM
JetBrains YouTrack <2019.2.53938 - Info Disclosure
CVSS 4.3
CVE-2019-11748 MEDIUM
Firefox < 69.0 and Firefox ESR < 68.1.0 - Improper Preservation of Permissions in WebRTC
CVSS 6.5
CVE-2019-6791 MEDIUM
GitLab <11.5.8-11.7.1 - Privilege Escalation
CVSS 6.5
CVE-2019-6995 MEDIUM
GitLab <11.5.8-11.7.1 - Info Disclosure
CVSS 6.5
CVE-2018-12989 MEDIUM
Pearson VUE Certiport Console <2018-06-26 - Privilege Escalation
CVSS 6.7
CVE-2018-3762 MEDIUM
Nextcloud Server < 12.0.8 - Improper Access Control via File Preview Request
CVSS 4.3
CVE-2018-5163 HIGH
Firefox < 60 - Privilege Escalation
CVSS 8.1
CVE-2018-4115 CRITICAL
Apple <11.3, <10.13.4, <4.3 - Auth Bypass
CVSS 9.8
CVE-2017-8593 HIGH
Microsoft Win32k - Privilege Escalation
CVSS 7.0
CVE-2017-8590 HIGH
Microsoft Windows - Elevation of Privilege via CLFS Driver Memory Handling
CVSS 8.8
CVE-2017-8589 CRITICAL
Microsoft Windows - Remote Code Execution via Windows Search Memory Handling
CVSS 9.8
CVE-2017-8581 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.0
CVE-2017-8580 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.0
CVE-2017-8578 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.8
CVE-2017-8577 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.0
CVE-2017-8574 HIGH
Microsoft Windows 10 <1704 - Privilege Escalation
CVSS 7.0
CVE-2017-8573 HIGH
Microsoft Graphics - Privilege Escalation
CVSS 7.0
CVE-2017-8563 HIGH
Microsoft Windows < - Privilege Escalation
CVSS 8.1
CVE-2017-8562 HIGH
Microsoft Windows - Elevation of Privilege via ALPC Call Handling
CVSS 7.0
CVE-2017-8561 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.0
CVE-2017-8556 HIGH
Microsoft Graphics - Privilege Escalation
CVSS 7.0
CVE-2017-8467 HIGH
Microsoft Windows - Privilege Escalation
CVSS 7.0
CVE-2017-8579 HIGH
Windows 10 and Windows Server 2016 - Authenticated Elevation of Privilege via DirectX
CVSS 7.0
Details
Vulnerabilities 337