Vulnerabilities > Improper Preservation of Permissions

DATE CVE VULNERABILITY TITLE RISK
2019-10-02 CVE-2019-14956 Improper Preservation of Permissions vulnerability in Jetbrains Youtrack
JetBrains YouTrack before 2019.2.53938 was using incorrect settings, allowing a user without necessary permissions to get other project names.
network
low complexity
jetbrains CWE-281
4.0
2019-09-27 CVE-2019-11748 Improper Preservation of Permissions vulnerability in Mozilla Firefox and Firefox ESR
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context.
network
mozilla CWE-281
4.3
2019-09-09 CVE-2019-6791 Improper Preservation of Permissions vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1.
network
low complexity
gitlab CWE-281
4.0
2019-09-09 CVE-2019-6995 Improper Preservation of Permissions vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1.
network
low complexity
gitlab CWE-281
4.0
2018-08-03 CVE-2018-12989 Improper Preservation of Permissions vulnerability in Pearsonvue Console 8 and Iqsystem 7
The report-viewing feature in Pearson VUE Certiport Console 8 and IQSystem 7 before 2018-06-26 mishandles child processes and consequently launches Internet Explorer or Microsoft Edge as Administrator, which allows local users to gain privileges.
local
low complexity
pearsonvue CWE-281
7.2
2018-07-05 CVE-2018-3762 Improper Preservation of Permissions vulnerability in Nextcloud Server
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
network
low complexity
nextcloud CWE-281
4.3
2018-06-11 CVE-2018-5163 Improper Preservation of Permissions vulnerability in multiple products
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code.
network
high complexity
canonical mozilla CWE-281
5.1
2018-04-03 CVE-2018-4115 Improper Preservation of Permissions vulnerability in Apple products
An issue was discovered in certain Apple products.
network
low complexity
apple CWE-281
7.5
2017-08-08 CVE-2017-8593 Improper Preservation of Permissions vulnerability in Microsoft products
Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability".
6.9
2017-07-11 CVE-2017-8590 Improper Preservation of Permissions vulnerability in Microsoft products
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows Common Log File System (CLFS) driver handles objects in memory, aka "Windows CLFS Elevation of Privilege Vulnerability".
local
low complexity
microsoft CWE-281
4.6