Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2020-01-23 CVE-2019-19895 Incorrect Permission Assignment for Critical Resource vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system.
local
low complexity
ixpdata CWE-732
7.8
2020-01-23 CVE-2019-19894 Incorrect Permission Assignment for Critical Resource vulnerability in Ixpdata Easyinstall 6.2.13723
In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system.
local
low complexity
ixpdata CWE-732
5.5
2020-01-23 CVE-2012-2087 Incorrect Permission Assignment for Critical Resource vulnerability in Ispconfig 3.0.4.3
ISPConfig 3.0.4.3: the "Add new Webdav user" can chmod and chown entire server from client interface.
network
low complexity
ispconfig CWE-732
critical
9.8
2020-01-17 CVE-2019-14629 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Data Analytics Acceleration Library
Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-732
5.5
2020-01-17 CVE-2019-3683 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project.
network
low complexity
suse hp CWE-732
8.8
2020-01-16 CVE-2019-20327 Incorrect Permission Assignment for Critical Resource vulnerability in Centreon
Insecure permissions in cwrapper_perl in Centreon Infrastructure Monitoring Software through 19.10 allow local attackers to gain privileges.
local
low complexity
centreon CWE-732
7.8
2020-01-14 CVE-2019-16784 Incorrect Permission Assignment for Critical Resource vulnerability in Pyinstaller
In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which have his "TempPath" resolving to a world writable directory.
local
low complexity
pyinstaller CWE-732
7.8
2020-01-13 CVE-2019-19727 Incorrect Permission Assignment for Critical Resource vulnerability in multiple products
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 has weak slurmdbd.conf permissions.
local
low complexity
schedmd opensuse CWE-732
5.5
2020-01-03 CVE-2019-19263 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
network
low complexity
gitlab CWE-732
4.3
2020-01-03 CVE-2019-19262 Incorrect Permission Assignment for Critical Resource vulnerability in Gitlab
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
network
low complexity
gitlab CWE-732
4.3