CWE-732— Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.— MITRE CWE catalog
1,885 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-732page 12 of 38
- CVE-2019-16784HIGHCVSS 7.0EG 7.02020-01-14
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the c…
- CVE-2019-17051HIGHCVSS 7.8EG 7.82019-09-30
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute is not used for attachment files, as demonstrated by a one-click attack involving a drag-and-drop operation on a crafted Terminal file.
- CVE-2019-17388HIGHCVSS 7.8EG 7.82019-12-05
Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications.
- CVE-2019-1803MEDIUMCVSS 6.7EG 6.72019-05-03
A vulnerability in the filesystem management for the Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker with administrator rights to gain elevated privileges a…
- CVE-2019-18192HIGHCVSS 7.8EG 7.82019-10-17
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
- CVE-2019-18243MEDIUMCVSS 5.5EG 5.52021-02-18
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through the registry. This may allow privilege escalation.
- CVE-2019-18255MEDIUMCVSS 5.5EG 5.52021-02-18
HMI/SCADA iFIX (Versions 6.1 and prior) allows a local authenticated user to modify system-wide iFIX configurations through section objects. This may allow privilege escalation.
- CVE-2019-18409HIGHCVSS 7.8EG 7.82019-10-24
The ruby_parser-legacy (aka legacy) gem 1.0.0 for Ruby allows local privilege escalation because of world-writable files. For example, if the brakeman gem (which has a legacy dependency) 4.5.0 through 4.7.0 is used, a local user can insert…
- CVE-2019-18422HIGHCVSS 8.8EG 8.82019-10-31
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. Wh…
- CVE-2019-18446MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4. It has Insecure Permissions (issue 1 of 2).
- CVE-2019-18447MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4. It has Insecure Permissions.
- CVE-2019-18449MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the autocomplete feature. It has Insecure Permissions (issue 2 of 2).
- CVE-2019-18450MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition before 12.4 in the Project labels feature. It has Insecure Permissions.
- CVE-2019-18452MEDIUMCVSS 5.3EG 5.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4 when moving an issue to a public project from a private one. It has Insecure Permissions.
- CVE-2019-18453MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11.6 through 12.4 in the add comments via email feature. It has Insecure Permissions.
- CVE-2019-18456MEDIUMCVSS 5.3EG 5.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 8.17 through 12.4 in the Search feature provided by Elasticsearch integration.. It has Insecure Permissions (issue 1 of 4).
- CVE-2019-18459MEDIUMCVSS 5.3EG 5.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11.3 to 12.3 in the protected environments feature. It has Insecure Permissions (issue 3 of 4).
- CVE-2019-18462MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.4. It has Insecure Permissions.
- CVE-2019-18463MEDIUMCVSS 4.3EG 4.32019-11-26
An issue was discovered in GitLab Community and Enterprise Edition through 12.4. It has Insecure Permissions (issue 4 of 4).
- CVE-2019-18577MEDIUMCVSS 6.7EG 6.72020-03-13
Dell EMC XtremIO XMS versions prior to 6.3.0 contain an incorrect permission assignment vulnerability. A malicious local user with XtremIO xinstall privileges may exploit this vulnerability to gain root access.
- CVE-2019-18856HIGHCVSS 7.5EG 7.52019-11-11
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
- CVE-2019-18895HIGHCVSS 7.8EG 7.82019-11-14
Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
- CVE-2019-18899MEDIUMCVSS 6.2EG 6.22020-01-23
The apt-cacher-ng package of openSUSE Leap 15.1 runs operations in user owned directory /run/apt-cacher-ng with root privileges. This can allow local attackers to influence the outcome of these operations. This issue affects: openSUSE Leap…
- CVE-2019-18958HIGHCVSS 7.8EG 7.82019-11-21
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is …
- CVE-2019-19086MEDIUMCVSS 4.3EG 4.32020-01-03
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 1 of 2).
- CVE-2019-19087MEDIUMCVSS 4.3EG 4.32020-01-03
Gitlab Enterprise Edition (EE) before 12.5.1 has Insecure Permissions (issue 2 of 2).
- CVE-2019-19197HIGHCVSS 7.8EG 7.82019-11-21
IOCTL Handling in the kyrld.sys driver in Kyrol Internet Security 9.0.6.9 allows an attacker to achieve privilege escalation, denial-of-service, and code execution via usermode because 0x9C402401 using METHOD_NEITHER results in a read prim…
- CVE-2019-19216HIGHCVSS 8.8EG 8.82020-04-30
BMC Control-M/Agent 7.0.00.000 has an Insecure File Copy.
- CVE-2019-19218HIGHCVSS 7.5EG 7.52020-04-30
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.
- CVE-2019-19262MEDIUMCVSS 4.3EG 4.32020-01-03
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
- CVE-2019-19263MEDIUMCVSS 4.3EG 4.32020-01-03
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
- CVE-2019-19315HIGHCVSS 7.1EG 7.12019-12-17
NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \\.\mailslot\nlsX86ccMailslot mailslot.
- CVE-2019-19335MEDIUMCVSS 4.4EG 4.42020-03-18
During installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and `kubeadmin-password` files. Both files contain credentials used to authenticate to the OpenShift AP…
- CVE-2019-19341MEDIUMCVSS 5.5EG 5.52019-12-19
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and know…
- CVE-2019-19363HIGHCVSS 7.8EG 7.82020-01-24
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later…
- CVE-2019-19382HIGHCVSS 7.8EG 7.82019-12-03
Max Secure Anti Virus Plus 19.0.4.020 has Insecure Permissions on the installation directory. Local attackers can replace a .exe or .dll file to achieve privilege escalation.
- CVE-2019-1944HIGHCVSS 7.3EG 7.32019-08-07
Multiple vulnerabilities in the smart tunnel functionality of Cisco Adaptive Security Appliance (ASA) could allow an authenticated, local attacker to elevate privileges to the root user or load a malicious library file while the tunnel is …
- CVE-2019-19455HIGHCVSS 7.8EG 7.82020-08-03
Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamingEngine / manager / bin / in the Linux version of the server by writing arbitrary commands…
- CVE-2019-19522HIGHCVSS 7.8EG 7.82019-12-05
OpenBSD 6.6, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root's file can be written to /etc/skey or /var…
- CVE-2019-19727MEDIUMCVSS 5.5EG 5.52020-01-13
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
- CVE-2019-19736MEDIUMCVSS 6.1EG 6.12019-12-30
MFScripts YetiShare 3.5.2 through 4.5.3 does not set the HttpOnly flag on session cookies, allowing the cookie to be read by script, which can potentially be used by attackers to obtain the cookie via cross-site scripting.
- CVE-2019-19882HIGHCVSS 7.8EG 7.82019-12-18
shadow 4.8, in certain circumstances affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain root access because setuid programs are misconfigured. Specifically, this affects shadow 4.8 when compiled using --wit…
- CVE-2019-19894MEDIUMCVSS 5.5EG 5.52020-01-23
In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\I…
- CVE-2019-19895HIGHCVSS 7.8EG 7.82020-01-23
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement…
- CVE-2019-19915CRITICALCVSS 9.0EG 9.02019-12-19
The "301 Redirects - Easy Redirect Manager" plugin before 2.45 for WordPress allows users (with subscriber or greater access) to modify, delete, or inject redirect rules, and exploit XSS, with the /admin-ajax.php?action=eps_redirect_save a…
- CVE-2019-2001MEDIUMCVSS 5.5EG 5.52019-02-28
The permissions on /proc/iomem were world-readable. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel…
- CVE-2019-2023HIGHCVSS 7.8EG 7.82019-06-19
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID of the caller. This could allow an app to add or replace a HAL service with its own service, gaining code execution in…
- CVE-2019-20327HIGHCVSS 7.8EG 7.82020-01-16
Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges. (cwrapper_perl is a setuid executable allowing execution of Perl scripts with root privileges.)
- CVE-2019-20358HIGHCVSS 7.8EG 7.82020-01-30
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when execute…
- CVE-2019-20693MEDIUMCVSS 5.4EG 5.42020-04-16
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects WAC505 before 8.0.6.4 and WAC510 before 8.0.6.4.
Map vulnerabilities like CWE-732 to your infrastructure
EchelonGraph correlates every CVE — across CWE-732 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →