CWE-276
1,508 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,508)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexu...Show more |
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation. |
1Adobe 1Genuine Integrity Service Nov 21, 2024 Mar 25, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. |
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-201...Show more |
1Supsystic 1Pricing Table By Supsystic Nov 21, 2024 Mar 23, 2020 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated u...Show more |
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4. |
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. |
1Netsas 1Enigma Network Management Solution Nov 21, 2024 Mar 19, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g.,...Show more |
1Fortinet 4Fortibalancer 1000 Firmware Fortibalancer 2000 FirmwareFortibalancer 3000 Firmware+1 moreNov 21, 2024 Mar 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is ca...Show more |
1Fortinet 4Fortibalancer 1000 Firmware Fortibalancer 2000 FirmwareFortibalancer 3000 Firmware+1 moreNov 21, 2024 Mar 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is ca...Show more |
1Fortinet 4Fortibalancer 1000 Firmware Fortibalancer 2000 FirmwareFortibalancer 3000 Firmware+1 moreNov 21, 2024 Mar 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is ca...Show more |
Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially e...Show more |
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create r...Show more |
1Puppet 3Puppet Enterprise Puppet ServerPuppetdbNov 21, 2024 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for de...Show more |
1Tibco 2Spotfire Analytics Platform For Aws Spotfire ServerNov 21, 2024 Mar 11, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permission...Show more |
Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executab...Show more |
A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned files. |
1Apple 5Ipados Iphone OsMac Os X+2 moreNov 21, 2024 Feb 27, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with...Show more |
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /setti...Show more |