VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 32 of 79
  • CVE-2024-52946HigNov 18, 2024
    risk 0.50cvss 8.8epss 0.00

    An issue was discovered in LemonLDAP::NG before 2.20.1. An Improper Check during session refresh allows an authenticated user to raise their authentication level if the admin configured an "Adaptative authentication rule" with an increment instead of an absolute value.

  • CVE-2024-42681HigAug 15, 2024
    risk 0.50cvss 8.8epss 0.01

    Insecure Permissions vulnerability in xxl-job v.2.4.1 allows a remote attacker to execute arbitrary code via the Sub-Task ID component.

  • CVE-2024-36495HigJun 24, 2024
    risk 0.50cvss 7.7epss 0.00

    The application Faronics WINSelect (Standard + Enterprise) saves its configuration in an encrypted file on the file system which "Everyone" has read and write access to, path to file: C:\ProgramData\WINSelect\WINSelect.wsd The path for the affected WINSelect…

  • CVE-2024-27155HigJun 14, 2024
    risk 0.50cvss 7.7epss 0.00

    The Toshiba printers are vulnerable to a Local Privilege Escalation vulnerability. An attacker can remotely compromise any Toshiba printer. The programs can be replaced by malicious programs by any local or remote attacker. As for the affected products/models/versions, see the…

  • CVE-2022-48685HigApr 27, 2024
    risk 0.50cvss 7.7epss 0.00

    An issue was discovered in Logpoint 7.1 before 7.1.2. The daily executed cron file clean_secbi_old_logs is writable by all users and is executed as root, leading to privilege escalation.

  • CVE-2023-43496HigSep 20, 2023
    risk 0.50cvss 8.8epss 0.01

    Jenkins 2.423 and earlier, LTS 2.414.1 and earlier creates a temporary file in the system temporary directory with the default permissions for newly created files when installing a plugin from a URL, potentially allowing attackers with access to the system temporary directory to…

  • CVE-2023-25645HigJun 16, 2023
    risk 0.50cvss 7.7epss 0.00

    There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings, non-privileged application can perform functions that are protected with signature/privilege-level permissions. Exploitation of this vulnerability could clear…

  • CVE-2022-29178HigMay 20, 2022
    risk 0.50cvss 8.8epss 0.00

    Cilium is open source software for providing and securing network connectivity and loadbalancing between application workloads. Cilium prior to versions 1.9.16, 1.10.11, and 1.11.15 contains an incorrect default permissions vulnerability. Operating Systems with users belonging…

  • CVE-2020-8022HigJun 29, 2020
    risk 0.50cvss 7.7epss 0.01

    A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux…

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2017-18868HigMay 21, 2020
    risk 0.50cvss 7.7epss 0.01

    Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related to the network stack upon which the ZigBee protocol is built.

  • CVE-2025-59030HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.

  • CVE-2025-13025HigNov 11, 2025
    risk 0.49cvss 7.5epss 0.00

    Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.

  • CVE-2025-54530HigJul 28, 2025
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

  • CVE-2025-30706HigApr 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2024-55950HigDec 26, 2024
    risk 0.49cvss epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.216, Tabby terminal emulator contains overly permissive entitlements that are unnecessary for its core functionality and plugin system, creating potential security vulnerabilities. The application…

  • CVE-2024-49202HigDec 18, 2024
    risk 0.49cvss 7.6epss 0.00

    Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned, aka 64099. The fixed versions are 11.5.1.1, 11.5.2.1, 11.5.3.1, 11.5.4.5, 11.5.6.1, 11.6.0, 12.2.0.1, 12.3.0.1, 12.4.0.1, 12.5.0, and 24.4.0.

  • CVE-2024-44786HigNov 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in Meabilis CMS 1.0 allows attackers to access other users' address books via unspecified vectors.

  • CVE-2024-28058HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.00

    In RSA NetWitness (NW) Platform before 12.5.1, even when an administrator revokes the access of a specific user with an active session, an internal threat actor could impersonate the revoked user and gain unauthorized access to sensitive data.

  • CVE-2024-36063HigNov 7, 2024
    risk 0.49cvss 7.5epss 0.00

    The Goodwy com.goodwy.dialer (aka Right Dialer) application through 5.1.0 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.goodwy.dialer.activities.DialerActivity component.