← Back
CWE-276

1,555 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

JSON object

Loading...

CVEs (1,555)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openstack
2Essex
Folsom
Apr 30, 2026
Mar 8, 2013
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configu...Show more
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.Show less
1Adobe
1Coldfusion
Apr 21, 2026
Jan 17, 2013
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and...Show more
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.Show less
3Dracut Project
FedoraprojectRedhat
5Dracut
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive infor...Show more
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.Show less
2Debian
Mediawiki
2Debian Linux
Mediawiki
Apr 29, 2026
Jan 8, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning fun...Show more
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) leveraging an extension, as demonstrated by the CategoryTree, ExtTab, and InlineEditor extensions.Show less
1Google
1Chrome
Apr 29, 2026
Sep 19, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
1Google
1Chrome
Apr 29, 2026
Aug 3, 2011
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspe...Show more
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.Show less
1Google
1Chrome
Apr 29, 2026
May 3, 2011
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.
2Dracut Project
Udev Project
2Dracut
Udev
Apr 29, 2026
Dec 7, 2010
N/A· v4
N/A· v3
4.0 MEDIUM· v2
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
1Cpanel
1Cpanel
Apr 23, 2026
Sep 27, 2006
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
1Silvercity Project
1Silvercity
Apr 16, 2026
Jun 8, 2005
N/A· v4
7.8 HIGH· v3
3.7 LOW· v2
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
1Skype
1Skype
Apr 16, 2026
Dec 22, 2004
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct soci...Show more
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or other attacks.Show less
1Microsoft
1Windows Media Player
Apr 16, 2026
Dec 31, 2002
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.
1Mandrakesoft
1Mandrake Linux
Apr 16, 2026
Dec 31, 2002
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.
1Isc
1Bind
Apr 16, 2026
Jul 21, 2001
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obt...Show more
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.Show less
1Suse
1Suse Linux
Apr 16, 2026
Mar 1, 1999
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.