Vulnerabilities (CVE)

Filtered by CWE-276
Total 1238 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-31006 1 Apple 3 Macos, Tvos, Watchos 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.
CVE-2021-31000 1 Apple 5 Ipados, Iphone Os, Macos and 2 more 2024-11-21 4.3 MEDIUM 3.3 LOW
A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.2 and iPadOS 15.2, watchOS 8.3, macOS Monterey 12.1, tvOS 15.2. A malicious application may be able to read sensitive contact information.
CVE-2021-30999 1 Apple 2 Ipados, Iphone Os 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.6 and iPadOS 14.6. A user may be unable to fully delete browsing history.
CVE-2021-30750 1 Apple 1 Macos 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.
CVE-2021-30494 1 Razer 1 Synapse 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can create a file in an unintended directory (with some limitations).
CVE-2021-30493 1 Razer 1 Synapse 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log information. In other words, an attacker can create a file in an unintended directory (with some limitations).
CVE-2021-30490 2 Microsoft, Power-software-download 2 Windows, Viewpower 2024-11-21 N/A 7.8 HIGH
upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation.
CVE-2021-29052 1 Liferay 2 Dxp, Liferay Portal 2024-11-21 4.0 MEDIUM 4.3 MEDIUM
The Data Engine module in Liferay Portal 7.3.0 through 7.3.5, and Liferay DXP 7.3 before fix pack 1 does not check permissions in DataDefinitionResourceImpl.getSiteDataDefinitionByContentTypeByDataDefinitionKey, which allows remote authenticated users to view DDMStructures via GET API calls.
CVE-2021-29005 1 Rconfig 1 Rconfig 2024-11-21 9.0 HIGH 8.8 HIGH
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on server.
CVE-2021-28649 2 Microsoft, Trendmicro 2 Windows, Housecall For Home Networks 2024-11-21 4.4 MEDIUM 7.3 HIGH
An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator who is running a scan. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
CVE-2021-28271 1 Soyal 3 701clientsql, 701server, 701serversql 2024-11-21 6.5 MEDIUM 8.8 HIGH
Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an authenticated user to change the executable file with a binary choice. The vulnerability is due to improper permissions with the 'F' flag (Full) for 'Everyone'and 'Authenticated Users' group.
CVE-2021-27193 2 Microsoft, Netop 2 Windows, Vision Pro 2024-11-21 7.5 HIGH 9.8 CRITICAL
Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.
CVE-2021-27032 1 Autodesk 1 Licensing Services 2024-11-21 7.2 HIGH 7.8 HIGH
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited privileges could run any number of tools on a system to identify services that are configured with weak permissions and are running under elevated privileges. These weak permissions could allow all users on the operating system to modify the service configuration and take ownership of the service.
CVE-2021-26804 1 Centreon 1 Centreon Web 2024-11-21 4.0 MEDIUM 6.5 MEDIUM
Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validation by changing any file extension to ".gif", then uploading it in the "Administration/ Parameters/ Images" section of the application.
CVE-2021-26274 1 Ninjarmm 1 Ninjarmm 2024-11-21 3.6 LOW 7.1 HIGH
The Agent in NinjaRMM 5.0.909 has Insecure Permissions.
CVE-2021-25381 2 Google, Samsung 2 Android, Account 2024-11-21 4.6 MEDIUM 5.5 MEDIUM
Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25359 1 Google 1 Android 2024-11-21 2.1 LOW 4.0 MEDIUM
An improper SELinux policy prior to SMR APR-2021 Release 1 allows local attackers to access AP information without proper permissions via untrusted applications.
CVE-2021-25358 1 Google 1 Android 2024-11-21 2.1 LOW 4.0 MEDIUM
A vulnerability that stores IMSI values in an improper path prior to SMR APR-2021 Release 1 allows local attackers to access IMSI values without any permission via untrusted applications.
CVE-2021-25355 1 Samsung 1 Notes 2024-11-21 4.6 MEDIUM 5.5 MEDIUM
Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
CVE-2021-25319 1 Opensuse 1 Factory 2024-11-21 7.2 HIGH 7.8 HIGH
A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.