← Back
CWE-276

1,529 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,529)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Apr 29, 2026
May 3, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.
2Dracut Project
Udev Project
2Dracut
Udev
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
1Cpanel
1Cpanel
Apr 23, 2026
Sep 27, 2006
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
1Silvercity Project
1Silvercity
Apr 16, 2026
Jun 8, 2005
N/A· v4
7.8 HIGH· v3
3.7 LOW· v2
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
1Skype
1Skype
Apr 16, 2026
Dec 22, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct soci...Show more
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.Show less
1Microsoft
1Windows Media Player
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.
1Mandrakesoft
1Mandrake Linux
Apr 16, 2026
Dec 31, 2002
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.
1Isc
1Bind
Apr 16, 2026
Jul 21, 2001
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obt...Show more
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.Show less
1Suse
1Suse Linux
Apr 16, 2026
Mar 1, 1999
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.