CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 1Trusted Execution Engine Firmware Jun 17, 2026 Dec 18, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and...Show more |
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed a...Show more |
A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disc...Show more |
1Tibco 5Spotfire Analyst Spotfire Analytics Platform For AwsSpotfire Deployment Kit+2 moreJun 17, 2026 Dec 17, 2019 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Langu...Show more |
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enab...Show more |
1Jenkins 1Websphere Deployer Jun 17, 2026 Dec 17, 2019 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exis...Show more |
1Jenkins 1Build Failure Analyzer Jun 17, 2026 Dec 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression. |
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials...Show more |
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them. |
1Atlassian 1Application Links Jun 17, 2026 Dec 17, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The ListEntityLinksServlet resource in Application Links before version 5.0.12, from version 5.1.0 before version 5.2.11, from version 5.3.0 before version 5.3.7, from version 5.4.0 before 5.4.13, and from version 6.0.0...Show more |
1Intel 1Setup And Configuration Software Platform Discovery Utility Jun 17, 2026 Dec 16, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack. |
Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local acce...Show more |
1Intel 1Rapid Storage Technology Jun 17, 2026 Dec 16, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access. |
1Intel 1Dynamic Platform And Thermal Framework Jun 17, 2026 Dec 16, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially execute code at an elevated level of privilege. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Dec 10, 2019 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba,...Show more |
1Saltosystem 1Proaccess Space Jun 17, 2026 Dec 3, 2019 N/A· v4 5.5 MEDIUM· v3 6.6 MEDIUM· v2 An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is a...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Dec 2, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the...Show more |
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe. |
1Cloudera 1Data Science Workbench Nov 21, 2024 Nov 26, 2019 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder. |
Cloudera CDH has Insecure Permissions because ALL cannot be revoked.This affects 5.x through 5.15.1 and 6.x through 6.0.1. |