Vulnerabilities > Incorrect Permission Assignment for Critical Resource

DATE CVE VULNERABILITY TITLE RISK
2019-07-22 CVE-2018-2024 Incorrect Permission Assignment for Critical Resource vulnerability in IBM Qradar Security Information and Event Manager 7.2.0/7.3.0
IBM QRadar SIEM 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
network
low complexity
ibm CWE-732
8.1
2019-07-19 CVE-2019-1010101 Incorrect Permission Assignment for Critical Resource vulnerability in Akeo Rufus
Akeo Consulting Rufus 3.0 and earlier is affected by: Insecure Permissions.
network
low complexity
akeo CWE-732
7.5
2019-07-17 CVE-2019-5222 Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Honor Magic 2 Firmware Tonyal00B/Tonytl00B9.0.0.182(C00E180R2P2)
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1).
network
huawei CWE-732
4.3
2019-07-17 CVE-2019-12876 Incorrect Permission Assignment for Critical Resource vulnerability in Zohocorp products
Zoho ManageEngine ADManager Plus 6.6.5, ADSelfService Plus 5.7, and DesktopCentral 10.0.380 have Insecure Permissions, leading to Privilege Escalation from low level privileges to System.
network
zohocorp CWE-732
8.5
2019-07-15 CVE-2019-1010009 Incorrect Permission Assignment for Critical Resource vulnerability in Dglogik Dglux Server
DGLogik Inc DGLux Server All Versions is affected by: Insecure Permissions.
network
low complexity
dglogik CWE-732
7.5
2019-07-11 CVE-2019-12577 Incorrect Permission Assignment for Critical Resource vulnerability in Londontrustmedia Private Internet Access VPN Client 82
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges.
local
low complexity
londontrustmedia CWE-732
7.2
2019-07-09 CVE-2019-13142 Incorrect Permission Assignment for Critical Resource vulnerability in Razer Surround 1.1.63.0
The RzSurroundVADStreamingService (RzSurroundVADStreamingService.exe) in Razer Surround 1.1.63.0 runs as the SYSTEM user using an executable located in %PROGRAMDATA%\Razer\Synapse\Devices\Razer Surround\Driver\.
local
low complexity
razer CWE-732
6.6
2019-07-03 CVE-2019-13208 Incorrect Permission Assignment for Critical Resource vulnerability in Maxx Waves Maxx Audio 1.9.29.0
WavesSysSvc in Waves MAXX Audio allows privilege escalation because the General registry key has Full Control access for the Users group, leading to DLL side loading.
local
maxx CWE-732
4.4
2019-07-03 CVE-2018-14862 Incorrect Permission Assignment for Critical Resource vulnerability in Odoo 10.0/11.0/9.0
Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request.
network
low complexity
odoo CWE-732
5.5
2019-07-03 CVE-2018-14861 Incorrect Permission Assignment for Critical Resource vulnerability in Odoo 10.0/11.0
Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users.
network
low complexity
odoo CWE-732
4.0