CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A missing permission check in Jenkins Libvirt Slaves Plugin allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another m...Show more |
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin in form-related methods allowed users with Overall/Read access to enumerate credentials ID of credentials stored in Jenkins. |
A missing permission check in Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained thr...Show more |
A missing permission check in Jenkins Deploy WebLogic Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials, or determine whether a file or dire...Show more |
1Jenkins 1Dynatrace Application Monitoring Jun 17, 2026 Oct 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials. |
2Linuxfoundation Vmware3Cloud Foundation HarborHarbor Container RegistryJun 17, 2026 Oct 18, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project the...Show more |
1Cisco 1Telepresence Collaboration Endpoint Jun 17, 2026 Oct 16, 2019 N/A· v4 4.4 MEDIUM· v3 6.6 MEDIUM· v2 A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to...Show more |
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions. |
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user...Show more |
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially craf...Show more |
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check. This could lead to local escalation of privilege with no additional execution privilege...Show more |
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an a...Show more |
An issue was discovered in Kaseya VSA RMM through 9.5.0.22. When using the default configuration, the LAN Cache feature creates a local account FSAdminxxxxxxxxx (e.g., FSAdmin123456789) on the server that hosts the LAN C...Show more |
1Vernissage Project 1Vernissage Nov 21, 2024 Oct 10, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates. |
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates. |
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates. |
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates. |
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable. |
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem. |
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control. |