CWE-281
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
337 vulnerabilities with CWE-281
CVE-2024-44149
HIGH
macOS Sequoia <15 - Info Disclosure
CVSS 7.5
CVE-2024-40859
MEDIUM
macOS Sequoia <15 - Info Disclosure
CVSS 5.5
CVE-2024-40831
MEDIUM
macOS Sequoia <15 - Info Disclosure
CVSS 5.5
CVE-2024-40770
HIGH
macOS Sequoia <15 - Privilege Escalation
CVSS 7.5
CVE-2024-27858
MEDIUM
macOS Sequoia <15 - Info Disclosure
CVSS 5.5
CVE-2024-27795
HIGH
macOS Sequoia <15 - Info Disclosure
CVSS 7.5
CVE-2024-22121
MEDIUM
Zabbix Agent - Privilege Escalation
CVSS 6.1
CVE-2024-22114
MEDIUM
System Information Widget - Info Disclosure
CVSS 4.3
CVE-2024-23464
HIGH
Zscaler Client Connector <4.2.1 - Privilege Escalation
CVSS 7.2
CVE-2024-33892
HIGH
Cosy+ <21.2s10, <22.1s3 - Info Disclosure
CVSS 7.5
CVE-2024-40828
HIGH
macOS 12.0-12.7.5 13.0-13.6.7 14.0-14.5 - Privilege Escalation to Root
CVSS 7.8
CVE-2024-40824
MEDIUM
iPadOS < 17.6 - Privacy Preference Bypass via Improper Permission Preservation
CVSS 5.5
CVE-2024-40821
HIGH
macOS 12.0-12.7.5, <13.6.8, <14.6 - Unprotected User Data Exposure via Third-Party App Extension Sandbox Bypass
CVSS 7.1
CVE-2024-40811
MEDIUM
macOS Sonoma <14.6 - Info Disclosure
CVSS 5.5
CVE-2024-40805
HIGH
watchOS 10.6-macOS Sonoma 14.6-iOS 17.6-iPadOS 17.6-tvOS 17.6 - Pri...
CVSS 7.1
CVE-2024-40800
MEDIUM
macOS 12.0-12.7.5, 13.0-13.6.7, 14.0-14.5 - Unprotected User Data Exposure via Input Validation Issue
CVSS 5.5
CVE-2024-27888
MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 5.5
CVE-2024-39902
MEDIUM
Tuleap <15.10.99.128-15.9-8 - Info Disclosure
CVSS 4.8
CVE-2024-29080
MEDIUM
HP Display Control - Privilege Escalation
CVSS 6.5
CVE-2024-2819
MEDIUM
Hitachi Ops Center Common Services <11.0.2-00 - Privilege Escalation
CVSS 5.1
CVE-2024-36532
CRITICAL
kruise <1.6.2 - Privilege Escalation
CVSS 10.0
CVE-2024-38361
LOW
Spicedb < 1.33.1 - Incorrect Permission Resolution via Exclusion Dispatcher
CVSS 3.7
CVE-2024-37882
HIGH
Nextcloud Server 23.0.0-23.0.12.16 and 26.0.0-26.0.12 - Improper Access Control via Share Permission Escalation
CVSS 8.1
CVE-2024-3291
HIGH
Nessus Agent <10.6.4 - Privilege Escalation
CVSS 7.8
CVE-2024-3289
HIGH
Nessus <10.7.3 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities
337