CWE-732

High likelihood

Incorrect Permission Assignment for Critical Resource

Parent: CWE-285 - Improper Authorization

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

1,624 vulnerabilities with CWE-732
CVE-2017-8665 HIGH
Microsoft Xamarin.ios < 10.11 - Incorrect Permission Assignment
CVSS 7.8
CVE-2017-11156 HIGH
Synology Download Station - Incorrect Permission Assignment
CVSS 7.8
CVE-2017-11437 MEDIUM
Gitlab - Incorrect Permission Assignment
CVSS 6.5
CVE-2017-9494 MEDIUM
Motorola MX011ANM <MX011AN_2.9p6s1_PROD_sey - RCE
CVSS 5.3
CVE-2017-9482 CRITICAL
Cisco DPC3939 - Privilege Escalation
CVSS 9.8
CVE-2017-9479 CRITICAL
Cisco DPC3939 - RCE
CVSS 9.8
CVE-2017-11422 HIGH
Statamic < 2.6.0 - Incorrect Permission Assignment
CVSS 8.8
CVE-2017-1000022 HIGH
LogicalDoc CE <7.5.3 - Privilege Escalation
CVSS 8.8
CVE-2017-0703 HIGH
Android <7.1.2 - Privilege Escalation
CVSS 7.8
CVE-2017-9615 CRITICAL
Cognito Software Moneyworks <8.0.3 - Info Disclosure
CVSS 9.8
CVE-2017-9780 HIGH
Flatpak <0.8.7 - Privilege Escalation
CVSS 7.8
CVE-2017-8450 HIGH
Elastic X-pack - Information Disclosure
CVSS 7.5
CVE-2017-8449 MEDIUM
Elastic X-pack < 5.2.2 - Information Disclosure
CVSS 5.9
CVE-2017-9602 CRITICAL
KBVault Mysql Free Knowledge Base <0.16a - RCE
CVSS 9.8
CVE-2017-9606 HIGH
Infotecs ViPNet Client and Coordinator <4.3.2-42442 - Privilege Escalation via Trojan Update
CVSS 7.3
CVE-2017-7563 HIGH
ARM Trusted Firmware 1.3 - Memory Corruption
CVSS 8.1
CVE-2017-9462 HIGH
Mercurial <4.1.3 - RCE
CVSS 8.8
CVE-2017-7337 CRITICAL
Fortinet FortiPortal <4.0.0 - Info Disclosure
CVSS 9.1
CVE-2017-9136 HIGH
Mimosa Client Radios <2.2.3 - Code Injection
CVSS 7.5
CVE-2017-9079 MEDIUM
Dropbear <2017.75 - Info Disclosure
CVSS 4.7
CVE-2017-7493 HIGH
Qemu - Privilege Escalation
CVSS 7.8
CVE-2017-0601 MEDIUM
Google Android - Incorrect Permission Assignment
CVSS 5.5
CVE-2017-0593 HIGH
Google Android - Incorrect Permission Assignment
CVSS 7.8
CVE-2017-8858 CRITICAL
Veritas Netbackup < 8.0 - Incorrect Permission Assignment
CVSS 9.8
CVE-2017-8857 CRITICAL
Veritas Netbackup < 8.0 - Incorrect Permission Assignment
CVSS 9.8
Details
Vulnerabilities 1,624
Exploit Likelihood High