CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create r...Show more |
1Puppet 3Puppet Enterprise Puppet ServerPuppetdbJun 17, 2026 Mar 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for de...Show more |
1Tibco 2Spotfire Analytics Platform For Aws Spotfire ServerJun 17, 2026 Mar 11, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permission...Show more |
Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executab...Show more |
A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned files. |
1Apple 5Ipados Iphone OsMac Os X+2 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The issue was addressed with improved permissions logic. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with...Show more |
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /setti...Show more |
Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access. |
Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Renesas Electronics Usb 3.0 Driver Jun 17, 2026 Feb 13, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. |
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permission from another app due to a permission bypass. This could lead to local escalation of privilege wi...Show more |
1Jenkins 1Pipeline Github Notify Step Jun 17, 2026 Feb 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. |
1Jenkins 1Pipeline Github Notify Step Jun 17, 2026 Feb 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Pipeline GitHub Notify Step Plugin 1.0.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs ob...Show more |
1Qualcomm 29Apq8053 Firmware Apq8096au FirmwareApq8098 Firmware+26 moreJun 17, 2026 Feb 7, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 APKs without proper permission may bind to CallEnhancementService and can lead to unauthorized access to call status in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon...Show more |
1Atlassian 4Jira Jira Data CenterJira Server+1 moreJun 17, 2026 Feb 6, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do no...Show more |
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions. |
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). |
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2). |
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission |