The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local privilege escalation issue due to insecure permissions
All versions of the NVIDIA GPU Display Driver contain a vulnerability in the GPU firmware where incorrect access control
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain acces
Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable
In Flatpak before 0.8.7, a third-party app repository could include malicious apps that contain files with inappropriate
A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsear
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
Razer Synapse 2.20.15.1104 and earlier uses weak permissions for the Devices directory, which allows local users to gain
An Incorrect Permission Assignment for Critical Resource issue was discovered in Advantech WebAccess versions prior to V
A elevation of privilege vulnerability in the Android framework (windowmanager). Product: Android. Versions: 4.4.4, 5.0.
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-serve
The init script in the Gentoo app-admin/logstash-bin package before 5.5.3 and 5.6.x before 5.6.1 has "chown -R" calls fo
An improper access control vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and pri
The installation scripts in the Gentoo dev-db/mysql, dev-db/mariadb, dev-db/percona-server, dev-db/mysql-cluster, and de
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access t
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a
In Apache Hadoop versions 2.6.1 to 2.6.5, 2.7.0 to 2.7.3, and 3.0.0-alpha1, if a file in an encryption zone with access
The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for
PNP4Nagios through 0.6.26 has /usr/bin/npcd and npcd.cfg owned by an unprivileged account but root code execution depend
An elevation of privilege vulnerability in the Android framework (device policy client). Product: Android. Versions: 6.0
An elevation of privilege vulnerability in the Android framework (window manager). Product: Android. Versions: 8.0. Andr
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file i
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper
An elevation of privilege vulnerability in the kernel scsi driver. Product: Android. Versions: Android kernel. Android I
All versions of NVIDIA GPU and GeForce Experience installer contain a vulnerability where it fails to set proper permiss
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi
A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1
Codiad(full version) is vulnerable to write anything to configure file in the installation resulting upload a webshell.
Scubez Posty Readymade Classifieds has Incorrect Access Control for visiting admin/user_activate_submit.php (aka the bac
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, wh
Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physic
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the abil
In Apache Impala (incubating) before 2.10.0, a malicious user with "ALTER" permissions on an Impala table can access any
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); Default
In Octopus before 3.17.7, an authenticated user who was explicitly granted the permission to invite new users (aka UserI
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules
FusionCompute V100R005C00 and V100R005C10 have an improper authorization vulnerability due to improper permission settin
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permissi
X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permission
The OS Installation Management component in CA Client Automation r12.9, r14.0, and r14.0 SP1 places an encrypted passwor
An Elevation of Privilege vulnerability in Bluetooth could potentially enable a local malicious application to accept ha
It was found that rhnsd PID files are created as world-writable that allows local attackers to fill the disks or to kill
IBM Security Guardium 10.0 specifies permissions for a security-critical resource in a way that allows that resource to
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started