CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The address-management feature in xt:Commerce 5.1 to 6.2.2 allows remote authenticated users to zero out other user's stored addresses by manipulating an id field in the POST request for altering an address. |
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated. |
1Abb 3800xa System Compact HmiControl Builder SafeJun 17, 2026 Apr 29, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0,...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxJun 17, 2026 Apr 24, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were...Show more |
The keygen protocol implementation in Binance tss-lib before 1.2.0 allows attackers to generate crafted h1 and h2 parameters in order to compromise a signing round or obtain sensitive information from other parties. |
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network. |
1Supsystic 1Data Tables Generator Jun 17, 2026 Apr 23, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The data-tables-generator-by-supsystic plugin before 1.9.92 for WordPress lacks capability checks for AJAX actions. |
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators. |
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file. |
Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow an authenticated user to access data and perform unauthorized actions due to inadequate permission checks. IBM X-ForceID: 175980. |
1Ibm 1Qradar Security Information And Event Manager Jun 17, 2026 Apr 15, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a local user to gain escalated privileges due to weak file permissions. IBM X-ForceID: 175846. |
An issue was discovered in AndyOS Andy versions up to 46.11.113. By default, it starts telnet and ssh (ports 22 and 23) with root privileges in the emulated Android system. This can be exploited by remote attackers to ga...Show more |
1S3india 1Husky Rtu 6049 E70 Firmware Jun 17, 2026 Apr 14, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default per...Show more |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports ChromeDebian Linux+2 moreJun 17, 2026 Apr 13, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page. |