CWE-277
73 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-277page 1 of 2
- CVE-2018-14335MEDIUMCVSS 6.5EG 6.52018-07-24
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
- CVE-2018-25111MEDIUMCVSS 5.1EG 5.12025-05-31
django-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.
- CVE-2019-5068MEDIUMCVSS 4.4EG 4.42019-11-05
An exploitable shared memory permissions vulnerability exists in the functionality of X11 Mesa 3D Graphics Library 19.1.2. An attacker can access the shared memory without any specific permissions to trigger this vulnerability.
- CVE-2020-5343HIGHCVSS 7.3EG 7.32020-05-04
Dell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissions vulnerability. A local authenticated malicious user with low privileges could exploit this vul…
- CVE-2021-24031MEDIUMCVSS 5.5EG 5.52021-03-04
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file permissions (matching the input) would only be set at completion time. Output files could therefore be readable or writ…
- CVE-2021-24032MEDIUMCVSS 4.7EG 4.72021-03-04
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards. Output files co…
- CVE-2021-32725LOWCVSS 3.5EG 3.52021-07-12
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in ver…
- CVE-2021-41170CRITICALCVSS 9.8EG 9.82021-11-08
neoan3-apps/template is a neoan3 minimal template engine. Versions prior to 1.1.1 have allowed for passing in closures directly into the template engine. As a result values that are callable are executed by the template engine. The issue a…
- CVE-2022-33898MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-36377MEDIUMCVSS 6.7EG 7.82022-11-11
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privil…
- CVE-2022-38103MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access
- CVE-2022-41658MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41687MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-41700MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-46656MEDIUMCVSS 6.7EG 6.72023-05-10
Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-27842HIGHCVSS 8.8EG 8.82023-03-21
Insecure Permissions vulnerability found in Extplorer File manager eXtplorer v.2.1.15 allows a remote attacker to execute arbitrary code via the index.php compenent
- CVE-2023-28207MEDIUMCVSS 5.5EG 5.52025-03-21
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plug-in may be able to inherit app permissions and access user data.
- CVE-2023-28658MEDIUMCVSS 6.7EG 6.72023-08-11
Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-29065MEDIUMCVSS 4.1EG 4.12023-11-28
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in t…
- CVE-2023-33870MEDIUMCVSS 6.7EG 7.82024-02-14
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-33990HIGHCVSS 7.8EG 7.82023-07-11
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory ob…
- CVE-2023-34314MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-34391HIGHCVSS 7.4EG 7.42023-08-31
Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecu…
- CVE-2023-34997MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-38541MEDIUMCVSS 6.7EG 6.72024-01-19
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via loc…
- CVE-2023-39230MEDIUMCVSS 6.7EG 6.72023-11-14
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-45736MEDIUMCVSS 6.7EG 6.72024-05-16
Insecure inherited permissions in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-21835MEDIUMCVSS 6.7EG 6.72024-05-16
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-23233HIGHCVSS 7.8EG 7.82024-03-08
This issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to this app may be used by a malicious app.
- CVE-2024-23908MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Flexlm License Daemons for Intel(R) FPGA software before version v11.19.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-25561MEDIUMCVSS 6.7EG 6.72024-08-14
Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-26574HIGHCVSS 7.8EG 7.82024-04-08
Insecure Permissions vulnerability in Wondershare Filmora v.13.0.51 allows a local attacker to execute arbitrary code via a crafted script to the WSNativePushService.exe
- CVE-2024-27674HIGHCVSS 7.8EG 7.82024-04-03
Macro Expert through 4.9.4 allows BUILTIN\Users:(OI)(CI)(M) access to the "%PROGRAMFILES(X86)%\GrassSoft\Macro Expert" folder and thus an unprivileged user can escalate to SYSTEM by replacing the MacroService.exe binary.
- CVE-2024-27822HIGHCVSS 7.8EG 7.42024-05-14
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to gain root privileges.
- CVE-2024-27825HIGHCVSS 7.1EG 7.82024-05-14
A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sonoma 14.5. An app may be able to bypass certain Privacy preferences.
- CVE-2024-27834MEDIUMCVSS 5.5EG 8.12024-05-14
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may …
- CVE-2024-27847MEDIUMCVSS 5.5EG 7.42024-05-14
This issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Monterey 12.7.5, macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be able to bypass Privacy preferences.
- CVE-2024-27848HIGHCVSS 7.8EG 7.82024-06-10
This issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A malicious app may be able to gain root privileges.
- CVE-2024-29417HIGHCVSS 8.4EG 8.42024-05-03
Insecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password reset function.
- CVE-2024-34329HIGHCVSS 8.4EG 8.42024-07-22
Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.
- CVE-2024-36276MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-36294MEDIUMCVSS 6.7EG 6.72024-11-13
Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2024-36539CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in contour v1.28.3 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36540CRITICALCVSS 9.8EG 9.82024-07-24
Insecure permissions in external-secrets v0.9.16 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36542HIGHCVSS 8.8EG 8.82024-07-25
Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.
- CVE-2024-36691MEDIUMCVSS 6.3EG 6.32024-06-12
Insecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify users' account information.
- CVE-2024-39877HIGHCVSS 8.8EG 8.82024-07-17
Apache Airflow 2.4.0, and versions before 2.9.3, has a vulnerability that allows authenticated DAG authors to craft a doc_md parameter in a way that could execute arbitrary code in the scheduler context, which should be forbidden according…
- CVE-2024-41601HIGHCVSS 7.5EG 7.52024-07-19
Insecure Permissions vulnerability in lin-CMS v.0.2.0 and before allows a remote attacker to obtain sensitive information via the login method in the UserController.java component.
- CVE-2024-42681HIGHCVSS 8.8EG 8.82024-08-15
Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.
- CVE-2024-45599LOWCVSS 3.8EG 3.82024-09-25
Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run on the machine is able to access the camera or the microphone with…
Map vulnerabilities like CWE-277 to your infrastructure
EchelonGraph correlates every CVE — across CWE-277 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →