CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2023-0975 HIGH
Trellix Agent for Windows <5.7.8 - Privilege Escalation
CVSS 8.2
CVE-2023-28668 CRITICAL
Jenkins Role-based Authorization Strategy Plugin <587.v2872c41fa_e5...
CVSS 9.8
CVE-2023-28647 MEDIUM
Nextcloud iOS <4.7.0 - Privilege Escalation
CVSS 4.4
CVE-2023-28646 MEDIUM
Nextcloud android <3.24.1 - Info Disclosure
CVSS 4.4
CVE-2023-28642 MEDIUM
runc < 1.1.5 - AppArmor Bypass via Symlinked /proc
CVSS 6.1
CVE-2023-25809 MEDIUM
runc < 1.1.5 - Unauthenticated Permission Overwrite in /sys/fs/cgroup
CVSS 5.0
CVE-2023-25817 LOW
Nextcloud Server 24.0.0-24.0.8 - Unauthorized File Deletion via Permission Escalation
CVSS 3.5
CVE-2023-21464 MEDIUM
Samsung Calendar <12.4.02.9000-12.3.08.2000 - Info Disclosure
CVSS 4.0
CVE-2023-22738 MEDIUM
vantage6 <3.8.0 - Privilege Escalation
CVSS 6.3
CVE-2023-25812 MEDIUM
Minio >=2020-04-10t03-34-42z <2023-02-17t17-52-43z - Improper Preservation of Permissions via BypassGoverance Policy
CVSS 6.5
CVE-2022-47637 MEDIUM
XAMPP <= 8.1.12 - Unauthenticated Arbitrary File Write via Installer
CVSS 6.7
CVE-2022-43910 HIGH
IBM Security Guardium 11.3 - Privilege Escalation
CVSS 8.4
CVE-2022-48301 HIGH
Bundle Management Module - Privilege Escalation
CVSS 7.5
CVE-2022-48296 MEDIUM
Huawei EMUI and HarmonyOS - Improper Preservation of Permissions in SystemUI
CVSS 5.3
CVE-2022-48295 HIGH
IHwAntiMalPlugin - Privilege Escalation
CVSS 7.5
CVE-2022-4139 HIGH
Linux Kernel - Use-After-Free in i915 GPU Driver
CVSS 7.8
CVE-2022-42260 HIGH
NVIDIA vGPU < 11.11 - Unauthenticated Privilege Escalation via D-Bus Configuration File
CVSS 7.8
CVE-2022-38473 HIGH
Thunderbird/Firefox < 102.2/<91.13/<104 - SSRF
CVSS 8.8
CVE-2022-47547 MEDIUM
GossipSub 1.1 - Improper Preservation of Permissions
CVSS 5.3
CVE-2022-4326 MEDIUM
Trellix Endpoint Agent <V35.31.22 - Privilege Escalation
CVSS 5.5
CVE-2022-41963 LOW
BigBlueButton <2.4.3 - Info Disclosure
CVSS 2.7
CVE-2022-31608 HIGH
NVIDIA GPU Display Driver for Linux - RCE
CVSS 7.8
CVE-2022-26024 MEDIUM
Intel(R) NUC HDMI Firmware Update Tool - Privilege Escalation
CVSS 6.7
CVE-2022-44020 MEDIUM
OpenStack Sushy-Tools <0.21.0-VirtualBMC <2.2.2 - Info Disclosure
CVSS 5.5
CVE-2022-41708 MEDIUM
Relatedcode's Messenger <7bcd20b - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 337