Vulnerabilities > Improper Preservation of Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-07-15 CVE-2020-15496 Improper Preservation of Permissions vulnerability in Acronis True Image
Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
local
low complexity
acronis CWE-281
4.6
2021-06-22 CVE-2021-22382 Improper Preservation of Permissions vulnerability in Huawei E3372 Firmware and E8372 Firmware
Huawei LTE USB Dongle products have an improper permission assignment vulnerability.
local
huawei CWE-281
4.4
2021-06-10 CVE-2021-21735 Improper Preservation of Permissions vulnerability in ZTE Zxhn H168N Firmware
A ZTE product has an information leak vulnerability.
network
low complexity
zte CWE-281
4.0
2021-06-09 CVE-2021-0074 Improper Preservation of Permissions vulnerability in Intel Computing Improvement Program
Improper permissions in the installer for the Intel(R) Computing Improvement Program software before version 2.4.5982 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-281
4.6
2021-06-09 CVE-2020-27383 Improper Preservation of Permissions vulnerability in Blizzard Battle.Net 1.27.1.12428
Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice.
local
low complexity
blizzard CWE-281
4.6
2021-06-01 CVE-2021-3495 Improper Preservation of Permissions vulnerability in multiple products
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7.
network
low complexity
netlify redhat CWE-281
6.5
2021-05-13 CVE-2021-22137 Improper Preservation of Permissions vulnerability in Elastic Elasticsearch
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used.
network
low complexity
elastic CWE-281
5.3
2021-05-11 CVE-2021-30482 Improper Preservation of Permissions vulnerability in Jetbrains Upsource
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
network
low complexity
jetbrains CWE-281
5.0
2021-05-06 CVE-2020-18890 Improper Preservation of Permissions vulnerability in Puppycms 5.1
Rmote Code Execution (RCE) vulnerability in puppyCMS v5.1 due to insecure permissions, which could let a remote malicious user getshell via /admin/functions.php.
network
low complexity
puppycms CWE-281
7.5
2021-03-15 CVE-2021-3418 Improper Preservation of Permissions vulnerability in GNU Grub2
If certificates that signed grub are installed into db, grub can be booted directly.
local
gnu CWE-281
4.4