Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2021-06-22 CVE-2021-0572 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 11.0
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-732
5.5
2021-06-16 CVE-2021-27483 Incorrect Permission Assignment for Critical Resource vulnerability in Zoll Defibrillator Dashboard
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
local
low complexity
zoll CWE-732
7.8
2021-06-11 CVE-2021-0477 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android
In notifyScreenshotError of ScreenshotNotificationsController.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-732
7.8
2021-06-11 CVE-2021-25393 Incorrect Permission Assignment for Critical Resource vulnerability in Google Android 10.0/11.0
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
local
low complexity
google CWE-732
5.5
2021-06-10 CVE-2021-23022 Incorrect Permission Assignment for Critical Resource vulnerability in F5 products
On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's temporary folder has weak file and folder permissions.
local
low complexity
f5 CWE-732
7.8
2021-06-10 CVE-2021-31929 Incorrect Permission Assignment for Critical Resource vulnerability in Annexcloud Loyalty Experience Platform
Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and settings, such as fraud prevention, coupon groups, email templates, or referrals.
network
low complexity
annexcloud CWE-732
4.3
2021-06-09 CVE-2021-0055 Incorrect Permission Assignment for Critical Resource vulnerability in Intel products
Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2021-06-09 CVE-2021-0056 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Lapbc510 Firmware and Lapbc710 Firmware
Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2021-06-09 CVE-2021-0077 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Vtune Profiler 2017/2018/2019
Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2021-06-09 CVE-2021-0102 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Unite
Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8