← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Android
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...Show more
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206842Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...Show more
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145207098Show less
1Google
1Android
Jun 17, 2026
Jun 11, 2020
N/A· v4
7.3 HIGH· v3
4.4 MEDIUM· v2
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User...Show more
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145136060Show less
1Apple
1Mac Os X
Jun 17, 2026
Jun 9, 2020
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to gain root privileges.
1Citrix
1Workspace App
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Citrix Workspace App before 1912 on Windows has Insecure Permissions which allows local users to gain privileges during the uninstallation of the application.
1Citrix
1Workspace App
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Citrix Workspace App before 1912 on Windows has Insecure Permissions and an Unquoted Path vulnerability which allows local users to gain privileges during the uninstallation of the application.
1Openbrowser Project
1Openbrowser
Jun 17, 2026
Jun 8, 2020
N/A· v4
5.4 MEDIUM· v3
5.8 MEDIUM· v2
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
21Asus
BroadcomCanon+18 more
2175020 Z4a69a
5030 M2u92b5030 Z4a70a+214 more
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.Show less
1Dext5
1Dext5
Jun 17, 2026
Jun 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
2Fedoraproject
Targetcli Fb Project
2Fedora
Targetcli Fb
Jun 17, 2026
Jun 5, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
1Google
1Chrome
Jun 17, 2026
Jun 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
1Google
1Chrome
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
2Debian
Google
2Chrome
Debian Linux
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
2Debian
Google
2Chrome
Debian Linux
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
3Debian
GoogleOpensuse
4Backports
ChromeDebian Linux+1 more
Jun 17, 2026
Jun 3, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Ch...Show more
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.Show less
1Jenkins
1Project Inheritance
Jun 17, 2026
Jun 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.
1Jenkins
1Self Organizing Swarm Modules
Jun 17, 2026
Jun 3, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Self-Organizing Swarm Plug-in Modules Plugin 3.20 and earlier does not check permissions on API endpoints that allow adding and removing agent labels.
1Digi
1Xbee 2 Firmware
Nov 21, 2024
May 21, 2020
N/A· v4
7.7 HIGH· v3
5.5 MEDIUM· v2
Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.
4Debian
FedoraprojectGoogle+1 more
5Backports Sle
ChromeDebian Linux+2 more
Jun 17, 2026
May 21, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.