Vulnerabilities > Improper Preservation of Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-04-27 CVE-2021-3523 Improper Preservation of Permissions vulnerability in Redhat Apicast 2.0.0
A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse.
network
low complexity
redhat CWE-281
7.5
2022-04-21 CVE-2021-43708 Improper Preservation of Permissions vulnerability in Helpsystems Titus Data Classification 18.8.1910.140
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
local
low complexity
helpsystems CWE-281
5.5
2022-04-08 CVE-2022-24428 Improper Preservation of Permissions vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges.
network
low complexity
dell CWE-281
8.8
2022-04-01 CVE-2021-3847 Improper Preservation of Permissions vulnerability in multiple products
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount.
local
low complexity
linux fedoraproject CWE-281
7.8
2022-03-18 CVE-2022-22650 Improper Preservation of Permissions vulnerability in Apple mac OS X and Macos
This issue was addressed with improved checks.
local
low complexity
apple CWE-281
5.5
2022-03-16 CVE-2021-39695 Improper Preservation of Permissions vulnerability in Google Android 11.0
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code.
local
low complexity
google CWE-281
7.8
2022-03-16 CVE-2021-39704 Improper Preservation of Permissions vulnerability in Google Android 10.0/11.0/12.0
In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass.
local
low complexity
google CWE-281
7.8
2022-03-10 CVE-2022-24618 Improper Preservation of Permissions vulnerability in Heimdalsecurity Heimdal Premium Security 2.5.383/2.5.385/2.5.395
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Repair" on the MSI package located in C:\Windows\Installer.
local
low complexity
heimdalsecurity CWE-281
7.8
2022-02-21 CVE-2021-45008 Improper Preservation of Permissions vulnerability in Plesk 18.0.37
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights.
network
low complexity
plesk CWE-281
8.8
2022-02-09 CVE-2022-21203 Improper Preservation of Permissions vulnerability in Intel Quartus Prime
Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-281
7.8