VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 23 of 79
  • CVE-2023-25941HigApr 4, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS versions 8.2.x-9.5.0.x contain an elevation of privilege vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to Denial of service, escalation of privileges, and information disclosure. This vulnerability…

  • CVE-2023-21433HigFeb 9, 2023
    risk 0.51cvss 7.8epss 0.04

    Improper access control vulnerability in Galaxy Store prior to version 4.5.49.8 allows local attackers to install applications from Galaxy Store.

  • CVE-2022-31254HigFeb 7, 2023
    risk 0.51cvss 7.8epss 0.00

    A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt…

  • CVE-2022-23454HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

  • CVE-2022-23453HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.

  • CVE-2022-45099HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise

  • CVE-2022-47040HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in ASKEY router RTF3505VW-N1 BR_SV_g000_R3505VMN1001_s32_7 allows attackers to escalate privileges via running the tcpdump command after placing a crafted file in the /tmp directory and sending crafted packets through port 80.

  • CVE-2022-20456HigJan 26, 2023
    risk 0.51cvss 7.8epss 0.00

    In AutomaticZenRule of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-3155HigDec 22, 2022
    risk 0.51cvss 7.8epss 0.00

    When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to…

  • CVE-2022-20611HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20495HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In getEnabledAccessibilityServiceList of AccessibilityManager.java, there is a possible way to hide an accessibility service due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2022-20475HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In test of ResetTargetTaskHelper.java, there is a possible hijacking of any app which sets allowTaskReparenting="true" due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20474HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.00

    In readLazyValue of Parcel.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-1038HigDec 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A potential security vulnerability has been identified in the HP Jumpstart software, which might allow escalation of privilege. HP is recommending that customers uninstall HP Jumpstart and use myHP software.

  • CVE-2022-42718HigDec 1, 2022
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-20452HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In initializeFromParcelLocked of BaseBundle.java, there is a possible method arbitrary code execution due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20441HigNov 8, 2022
    risk 0.51cvss 7.8epss 0.00

    In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User…

  • CVE-2022-33182HigOct 25, 2022
    risk 0.51cvss 7.8epss 0.00

    A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload,…

  • CVE-2022-36438HigOct 18, 2022
    risk 0.51cvss 7.8epss 0.00

    AsusSwitch.exe on ASUS personal computers (running Windows) sets weak file permissions, leading to local privilege escalation (this also can be used to delete files within the system arbitrarily). This affects ASUS System Control Interface 3 before 3.1.5.0, and AsusSwitch.exe…

  • CVE-2022-20436HigOct 11, 2022
    risk 0.51cvss 7.8epss 0.00

    There is an unauthorized service in the system service. Since the component does not have permission check, resulting in Local Elevation of privilege.Product: AndroidVersions: Android SoCAndroid ID: A-242248369