Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-15336 Incorrect Permission Assignment for Critical Resource vulnerability in Lavamobiles Z61 Firmware
The Lava Z61 Turbo Android device with a build fingerprint of LAVA/Z61_Turbo/Z61_Turbo:8.1.0/O11019/1536917928:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.31) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
local
low complexity
lavamobiles CWE-732
2.1
2019-11-14 CVE-2019-15335 Incorrect Permission Assignment for Critical Resource vulnerability in Lavamobiles Z92 Firmware
The Lava Z92 Android device with a build fingerprint of LAVA/Z92/Z92:8.1.0/O11019/1535088037:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
local
low complexity
lavamobiles CWE-732
2.1
2019-11-14 CVE-2019-15334 Incorrect Permission Assignment for Critical Resource vulnerability in Lavamobiles Iris 88 Firmware
The Lava Iris 88 Go Android device with a build fingerprint of LAVA/iris88_go/iris88_go:8.1.0/O11019/1538188945:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
local
low complexity
lavamobiles CWE-732
2.1
2019-11-14 CVE-2019-15333 Incorrect Permission Assignment for Critical Resource vulnerability in Lavamobiles Flair Z1 Firmware
The Lava Flair Z1 Android device with a build fingerprint of LAVA/Z1/Z1:8.1.0/O11019/1536680131:user/release-keys contains a pre-installed app with a package name of com.android.lava.powersave app (versionCode=400, versionName=v4.0.27) that allows any app co-located on the device to programmatically disable and enable Wi-Fi without the corresponding access permission through an exported interface.
local
low complexity
lavamobiles CWE-732
2.1
2019-11-14 CVE-2012-1160 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
network
low complexity
moodle fedoraproject CWE-732
4.0
2019-11-12 CVE-2019-1457 Incorrect Permission Assignment for Critical Resource vulnerability in Microsoft Office 2016/2019
A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.
network
microsoft CWE-732
6.8
2019-11-11 CVE-2019-18856 Incorrect Permission Assignment for Critical Resource vulnerability in Drupal SVG Sanitizer
A Denial Of Service vulnerability exists in the SVG Sanitizer module through 8.x-1.0-alpha1 for Drupal because access to external resources with an SVG use element is mishandled.
network
low complexity
drupal CWE-732
5.0
2019-11-08 CVE-2019-13535 Incorrect Permission Assignment for Critical Resource vulnerability in Medtronic products
In Medtronic Valleylab FT10 Energy Platform (VLFT10GEN) version 2.1.0 and lower and version 2.0.3 and lower, and Valleylab LS10 Energy Platform (VLLS10GEN—not available in the United States) version 1.20.2 and lower, the RFID security mechanism does not apply read protection, allowing for full read access of the RFID security mechanism data.
local
low complexity
medtronic CWE-732
2.1
2019-11-08 CVE-2019-3425 Incorrect Permission Assignment for Critical Resource vulnerability in ZTE Zxupn-9000E Firmware
The 9000EV5.0R1B12 version, and all earlier versions of ZTE product ZXUPN-9000E are impacted by vulnerability of permission and access control.
network
low complexity
zte CWE-732
7.5
2019-11-08 CVE-2019-3866 Incorrect Permission Assignment for Critical Resource vulnerability in Redhat Openstack-Mistral
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable.
local
low complexity
redhat CWE-732
2.1