Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2022-03-02 CVE-2021-3631 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels.
local
high complexity
redhat netapp CWE-732
6.3
2022-03-01 CVE-2022-25010 Incorrect Permission Assignment for Critical Resource vulnerability in Stepmania 5.0.12/5.1.0
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the entire file system.
network
low complexity
stepmania CWE-732
critical
9.1
2022-02-25 CVE-2022-24327 Incorrect Permission Assignment for Critical Resource vulnerability in Jetbrains HUB
In JetBrains Hub before 2021.1.13890, integration with JetBrains Account exposed an API key with excessive permissions.
network
low complexity
jetbrains CWE-732
7.5
2022-02-25 CVE-2022-0247 Incorrect Permission Assignment for Critical Resource vulnerability in Google Fuchsia 4.1/4.1.1/4.1.2
An issue exists in Fuchsia where VMO data can be modified through access to copy-on-write snapshots.
local
low complexity
google CWE-732
5.5
2022-02-16 CVE-2021-3557 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
A flaw was found in argocd.
network
low complexity
argoproj redhat CWE-732
6.5
2022-02-11 CVE-2022-0483 Incorrect Permission Assignment for Critical Resource vulnerability in Acronis VSS Doctor
Local privilege escalation due to insecure folder permissions.
local
low complexity
acronis CWE-732
7.8
2022-02-11 CVE-2021-44521 Incorrect Permission Assignment for Critical Resource vulnerability in Apache Cassandra
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host.
network
low complexity
apache CWE-732
critical
9.1
2022-02-09 CVE-2021-39992 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Emui 12.0.0
There is an improper security permission configuration vulnerability on ACPU.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
local
low complexity
huawei CWE-732
7.8
2022-02-09 CVE-2022-0532 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
An incorrect sysctls validation vulnerability was found in CRI-O 1.18 and earlier.
network
high complexity
kubernetes redhat CWE-732
4.2
2022-02-04 CVE-2021-22284 Incorrect Permission Assignment for Critical Resource vulnerability in ABB OPC Server for AC 800M
Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server.
network
low complexity
abb CWE-732
8.8