Vulnerabilities > Improper Preservation of Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-11-12 CVE-2020-12332 Improper Preservation of Permissions vulnerability in Intel HID Event Filter Driver
Improper permissions in the installer for the Intel(R) HID Event Filter Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-281
4.6
2020-11-12 CVE-2020-12330 Improper Preservation of Permissions vulnerability in Intel Falcon 8+ UAS Asctec Thermal Viewer Firmware
Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-281
4.6
2020-10-16 CVE-2020-16910 Improper Preservation of Permissions vulnerability in Microsoft products
<p>A security feature bypass vulnerability exists when Microsoft Windows fails to handle file creation permissions, which could allow an attacker to create files in a protected Unified Extensible Firmware Interface (UEFI) location.</p> <p>To exploit this vulnerability, an attacker could run a specially crafted application to bypass Unified Extensible Firmware Interface (UEFI) variable security in Windows.</p> <p>The security update addresses the vulnerability by correcting security feature behavior to enforce permissions.</p>
local
low complexity
microsoft CWE-281
6.2
2020-10-05 CVE-2020-8182 Improper Preservation of Permissions vulnerability in Nextcloud Deck 0.8.0
Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves.
network
nextcloud CWE-281
6.0
2020-09-21 CVE-2020-6564 Improper Preservation of Permissions vulnerability in multiple products
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.
network
low complexity
debian opensuse google fedoraproject CWE-281
6.5
2020-09-18 CVE-2020-0405 Improper Preservation of Permissions vulnerability in Google Android 11.0
In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent.
local
low complexity
google CWE-281
4.6
2020-09-18 CVE-2020-0349 Improper Preservation of Permissions vulnerability in Google Android 11.0
In NFC, there is a possible out of bounds read due to a missing bounds check.
local
low complexity
google CWE-281
2.1
2020-09-18 CVE-2020-0331 Improper Preservation of Permissions vulnerability in Google Android 11.0
In Settings, there is a possible permissions bypass.
local
low complexity
google CWE-281
2.1
2020-09-18 CVE-2020-0327 Improper Preservation of Permissions vulnerability in Google Android 11.0
In core networking, there is a missing permission check.
local
low complexity
google CWE-281
2.1
2020-09-18 CVE-2020-0269 Improper Preservation of Permissions vulnerability in Google Android 11.0
In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-281
2.1