← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apereo
1Opencast
Jun 17, 2026
Jan 30, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is r...Show more
In Opencast before 7.6 and 8.1, users with the role ROLE_COURSE_ADMIN can use the user-utils endpoint to create new users not including the role ROLE_ADMIN. ROLE_COURSE_ADMIN is a non-standard role in Opencast which is referenced neither in the documentation nor in any code (except for tests) but only in the security configuration. From the name – implying an admin for a specific course – users would never expect that this role allows user creation. This issue is fixed in 7.6 and 8.1 which both ship a new default security configuration.Show less
1Hp
1Sgi Tempo
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.
1Hp
1Sgi Tempo
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
1Hp
1Sgi Tempo
Nov 21, 2024
Jan 27, 2020
N/A· v4
6.6 MEDIUM· v3
4.6 MEDIUM· v2
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
1Bitdefender
1Antivirus
Jun 17, 2026
Jan 27, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories. This issue affects: Bitdefender AV for Mac vers...Show more
An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories. This issue affects: Bitdefender AV for Mac versions prior to 8.0.0.Show less
1Opensuse
1Libzypp
Jun 17, 2026
Jan 24, 2020
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposin...Show more
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. This issue affects: SUSE CaaS Platform 3.0 libzypp versions prior to 16.21.2-27.68.1. SUSE Linux Enterprise Server 12 libzypp versions prior to 16.21.2-2.45.1. SUSE Linux Enterprise Server 15 17.19.0-3.34.1.Show less
1Suse
1Linux Enterprise Server
Jun 17, 2026
Jan 24, 2020
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versi...Show more
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to 081d081dcfaf61710bda34bc21c80c66276119aa.Show less
1Ixpdata
1Easyinstall
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e....Show more
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the target server and clients.Show less
1Fordnn
1Usersexportimport
Jun 17, 2026
Jan 21, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or C...Show more
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.Show less
1Intel
1Raid Web Console 3
Jun 17, 2026
Jan 17, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
1Cerberusftp
1Ftp Server
Jun 17, 2026
Jan 14, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and downl...Show more
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.Show less
1Zohocorp
1Manageengine Applications Manager
Jun 17, 2026
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious...Show more
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in “Authenticated Users” group can exploit privilege escalation and modify PostgreSQL configuration to execute arbitrary command to escalate and gain full system privilege user access and rights over the system.Show less
1Cipherdyne
1Fwknop
Nov 21, 2024
Jan 9, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.
1Webfactoryltd
1Minimal Coming Soon & Maintenance Mode
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
A flaw in the WordPress plugin, Minimal Coming Soon & Maintenance Mode through 2.15, allows authenticated users with basic access to export settings and change maintenance-mode themes.
1Mozilla
1Firefox
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepte...Show more
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.Show less
2Debian
Google
2Android
Debian Linux
Jun 17, 2026
Jan 8, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no...Show more
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-142938932Show less
1Open Xchange
1Open Xchange Appsuite
Jun 17, 2026
Jan 6, 2020
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
OX App Suite through 7.10.2 has Incorrect Access Control.
1Insteon
1Hub Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
INSTEON Hub 2242-222 lacks Web and API authentication
1Samsung
2Galaxy S3 Firmware
Galaxy S4 Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
4.3 MEDIUM· v3
2.1 LOW· v2
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
1Samsung
2Galaxy S3 Firmware
Galaxy S4 Firmware
Nov 21, 2024
Dec 27, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.