CWE-276
1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CVEs (1,555)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more9Debian Linux Enterprise LinuxEnterprise Linux Eus+6 moreJun 17, 2026 May 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. |
1Schneider Electric 2Modicon M221 Firmware Somachine BasicJun 17, 2026 May 22, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMach...Show more |
3Fedoraproject SambaSynology7Directory Server Diskstation ManagerFedora+4 moreJun 17, 2026 Apr 9, 2019 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This dir...Show more |
1Microsoft 2Windows 7 Windows Server 2008Jun 17, 2026 Apr 9, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest,...Show more |
Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information via the world readable configuration. |
1Synology 1Diskstation Manager Jan 14, 2025 Apr 1, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive information via the world readable configuration...Show more |
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a security concern with default privileged access to ADB and debug-fs. |
2Ibm Lenovo29Bladecenter Hs23 Firmware Bladecenter Hs23e FirmwareFlex System X220 M4 Firmware+26 moreJun 17, 2026 Nov 16, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A write protection lock bit was left unset after boot on an older generation of Lenovo and IBM System x servers, potentially allowing an attacker with administrator access to modify the subset of flash memory containing...Show more |
1Corsair 1Corsair Utility Engine Nov 21, 2024 Oct 11, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_...Show more |
1Martem 2Telem Gw6 Firmware Telem Gwm FirmwareNov 21, 2024 Oct 1, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Martem TELEM GW6/GWM versions prior to 2.0.87-4018403-k4 may allow unprivileged users to modify/upload a new system configuration or take the full control over the RTU using default credentials to connect to the RTU. |
2Redhat Sos Collector Project6Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+3 moreNov 21, 2024 Sep 27, 2018 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 It was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tool readable by any local user. A local attacker may use this flaw by waiting fo...Show more |
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor. |
1Intel 1Distribution For Python Nov 21, 2024 Sep 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access. |
1Intel 1Data Migration Software Nov 21, 2024 Sep 12, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using default directory permissions via local...Show more |
1Siemens 2Simatic Step 7 (tia Portal) Simatic Wincc (tia Portal)Nov 21, 2024 Aug 7, 2018 N/A· v4 8.6 HIGH· v3 4.4 MEDIUM· v2 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC ST...Show more |
1Siemens 2Simatic Step 7 (tia Portal) Simatic Wincc (tia Portal)Nov 21, 2024 Aug 7, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC ST...Show more |
4Fujitsu HpPhilips+1 more6Display Assistant Displayview ClickDisplayview Click Suite+3 moreNov 21, 2024 Jul 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays S...Show more |
The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permissions to the anonymous user. The DBPower U818A WIFI quadcopter drone runs an FTP server that by defa...Show more |
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file. |
SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installation folder, resulting in escalation of pri...Show more |