Data::DisjointSet::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_
Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL o
Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EX
Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EX
Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_E
Data::Intern::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL
Data::SpatialHash::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_
rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local back
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe
Dell PowerProtect Agent Service, version(s) prior to 20.1, contain(s) an Incorrect Permission Assignment for Critical Re
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.
The nohup utility in uutils coreutils creates its default output file, nohup.out, without specifying explicit restricted
The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Es
Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL o
Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdi
The application does not impose strict enough restrictions on directory access permissions, posing a risk that other mal
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could r
A flaw was found in nano. In environments with permissive umask settings, a local attacker can exploit incorrect directo
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co
Incorrect permission assignment in AMD µProf may allow a local user-privileged attacker to achieve privilege escalation,
Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability
An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulne
Incorrect Permission Assignment for Critical Resource vulnerability in ILM Informatique OpenConcerto allows Replace Bina
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Na
A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulne
An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local u
Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s vali
Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow bac
ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private k
Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code
Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to
Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrar
FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php acce
A security vulnerability has been identified in Planet9 due to incorrect file permissions assigned to an application exe
Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86
RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona
Under certain conditions SAP NetWeaver AS for ABAP and ABAP Platform (Internet Communication Framework) allows an attack
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execut
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_cre
The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma
Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive
FreeFloat FTP Server contains multiple critical design flaws that allow unauthenticated remote attackers to upload arbit
Frequently Asked Questions
What is CWE-732?
CWE-732 (CWE-732) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-732?
There are 1,937 CVE records associated with CWE-732 in our database. Of these, 135 are critical severity, 822 are high severity, and 619 are medium severity.
How can I protect against CWE-732 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-732 using AI-powered security agents.
Detect CWE-732 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-732 vulnerabilities across your infrastructure.
Get Started