CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 2Legion Phone2 Pro (l70081) Firmware Legion Phone Pro (l79031)firmwareJun 17, 2026 Nov 12, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data. |
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient. |
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious f...Show more |
1Bitdefender 2Endpoint Security Tools Total SecurityJun 17, 2026 Oct 28, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate pri...Show more |
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. |
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions. |
There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality. |
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. |
1Gestionaleopen 1Gestionale Open Jun 17, 2026 Oct 26, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.exe file located in bin folder and replace with a malicious file that would connect back to an attack...Show more |
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker...Show more |
1Cisco 1Identity Services Engine Jun 17, 2026 Oct 21, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restri...Show more |
ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically proximate attacker. |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Oct 18, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell. |
Insecure permission of chmod command on rConfig server 3.9.6 exists. After installing rConfig apache user may execute chmod as root without password which may let an attacker with low privilege to gain root access on ser...Show more |
Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions starting with 10.6 and up to 14.1.7 allowing users to read confidential Epic references. |
Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database). |
Nagios XI before 5.8.5 has Incorrect Permission Assignment for repairmysql.sh. |
Nagios XI before 5.8.5 has Incorrect Permission Assignment for migrate.php. |
SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalation which potentially allows command execution in the host operating system. This...Show more |
1Apple 6Ipados Iphone OsMac Os X+3 moreJun 17, 2026 Sep 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improv...Show more |