CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

329 vulnerabilities with CWE-281
CVE-2023-22738 MEDIUM
vantage6 <3.8.0 - Privilege Escalation
CVSS 6.3
CVE-2023-25812 MEDIUM
Minio >=2020-04-10t03-34-42z <2023-02-17t17-52-43z - Improper Preservation of Permissions via BypassGoverance Policy
CVSS 6.5
CVE-2022-47637 MEDIUM
XAMPP <= 8.1.12 - Unauthenticated Arbitrary File Write via Installer
CVSS 6.7
CVE-2022-43910 HIGH
IBM Security Guardium 11.3 - Privilege Escalation
CVSS 8.4
CVE-2022-48301 HIGH
Bundle Management Module - Privilege Escalation
CVSS 7.5
CVE-2022-48296 MEDIUM
Huawei EMUI and HarmonyOS - Improper Preservation of Permissions in SystemUI
CVSS 5.3
CVE-2022-48295 HIGH
IHwAntiMalPlugin - Privilege Escalation
CVSS 7.5
CVE-2022-4139 HIGH
Linux Kernel - Use-After-Free in i915 GPU Driver
CVSS 7.8
CVE-2022-42260 HIGH
NVIDIA vGPU < 11.11 - Unauthenticated Privilege Escalation via D-Bus Configuration File
CVSS 7.8
CVE-2022-38473 HIGH
Thunderbird/Firefox < 102.2/<91.13/<104 - SSRF
CVSS 8.8
CVE-2022-47547 MEDIUM
GossipSub 1.1 - Improper Preservation of Permissions
CVSS 5.3
CVE-2022-4326 MEDIUM
Trellix Endpoint Agent <V35.31.22 - Privilege Escalation
CVSS 5.5
CVE-2022-41963 LOW
BigBlueButton <2.4.3 - Info Disclosure
CVSS 2.7
CVE-2022-31608 HIGH
NVIDIA GPU Display Driver for Linux - RCE
CVSS 7.8
CVE-2022-26024 MEDIUM
Intel(R) NUC HDMI Firmware Update Tool - Privilege Escalation
CVSS 6.7
CVE-2022-44020 MEDIUM
OpenStack Sushy-Tools <0.21.0-VirtualBMC <2.2.2 - Info Disclosure
CVSS 5.5
CVE-2022-41708 MEDIUM
Relatedcode's Messenger <7bcd20b - Info Disclosure
CVSS 4.3
CVE-2022-36062 HIGH
Grafana <8.5.13, 9.0.9, 9.1.6 - Privilege Escalation
CVSS 7.6
CVE-2022-38577 HIGH
ProcessMaker <3.5.4 - Privilege Escalation
CVSS 8.8
CVE-2022-36102 MEDIUM
Shopware < 5.7.15 - ACL Bypass via Backend Admin Controller Notation
CVSS 6.3
CVE-2022-2787 MEDIUM
schroot < 1.6.13 - Denial of Service via Chroot Session Name Rules
CVSS 4.3
CVE-2022-31237 LOW
Dell PowerScale OneFS <9.2.1.12 & 9.3.0.5 - Info Disclosure
CVSS 3.3
CVE-2022-31262 HIGH
GOG Galaxy 2.0.46 - Privilege Escalation
CVSS 7.8
CVE-2022-22472 HIGH
IBM Spectrum Protect Plus - Auth Bypass
CVSS 8.8
CVE-2022-32969 MEDIUM
MetaMask <10.11.3 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 329