Skip to main content

CWE archive

CWE-281 CVEs

Programmatic archive

339 CVEs tagged with CWE-28131 Critical, 148 High, 133 Medium, 25 Low, 2 Unrated.

CVE-2021-3847

Published Apr 1, 2022

An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a n…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-22650

Published Mar 18, 2022

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A plug-in may be able to inheri…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-39704

Published Mar 16, 2022

In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39695

Published Mar 16, 2022

In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execut…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24618

Published Mar 10, 2022

Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-45008

Published Feb 21, 2022

Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-21203

Published Feb 9, 2022

Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escala…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0953

Published Dec 15, 2021

In setOnClickActivityIntent of SearchWidgetProvider.java, there is a possible way to access contacts and history bookmarks without permission due to an unsafe PendingIntent. This…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0927

Published Dec 15, 2021

In requestChannelBrowsable of TvInputManagerService.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-0704

Published Dec 15, 2021

In createNoCredentialsPermissionNotification and related functions of AccountManagerService.java, there is a possible way to retrieve accounts from the device without permissions…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37086

Published Dec 7, 2021

There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read s…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-37056

Published Dec 7, 2021

There is an Improper permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37006

Published Nov 23, 2021

There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affecte…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-39897

Published Nov 5, 2021

Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-30827

Published Oct 19, 2021

A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local at…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-41089

Published Oct 4, 2021

Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-30912

Published Aug 24, 2021

The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious applica…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38553

Published Aug 13, 2021

HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem p…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-29971

Published Aug 5, 2021

If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *Th…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-32465

Published Aug 4, 2021

An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass a…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort
Showing 226-250 of 339 CVEsPage 10 of 14