VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 33 of 79
  • CVE-2024-44228HigOct 28, 2024
    risk 0.49cvss 7.5epss 0.00

    This issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissions and access user data.

  • CVE-2024-44100HigOct 25, 2024
    risk 0.49cvss 7.5epss 0.00

    Android before 2024-10-05 on Google Pixel devices allows information disclosure in the modem component, A-299774545.

  • CVE-2024-44760HigAug 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the component /servlet/SnoopServlet of Shenzhou News Union Enterprise Management System v5.0 through v18.8 allows attackers to access sensitive information regarding the server.

  • CVE-2024-43114HigAug 6, 2024
    risk 0.49cvss 7.5epss 0.00

    In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions

  • CVE-2023-38370HigJun 27, 2024
    risk 0.49cvss 7.5epss 0.01

    IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1, under certain configurations, could allow a user on the network to install malicious packages. IBM X-Force ID: 261197.

  • CVE-2024-37038HigJun 12, 2024
    risk 0.49cvss 7.5epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.

  • CVE-2023-23976HigApr 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect Default Permissions vulnerability in Metagauss RegistrationMagic allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects RegistrationMagic: from n/a through 5.1.9.2.

  • CVE-2023-52545HigApr 8, 2024
    risk 0.49cvss 7.5epss 0.00

    Vulnerability of undefined permissions in the Calendar app. Impact: Successful exploitation of this vulnerability will affect availability.

  • CVE-2024-22889HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.

  • CVE-2023-49338HigFeb 28, 2024
    risk 0.49cvss 7.5epss 0.01

    Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.

  • CVE-2023-52379HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission control vulnerability in the calendarProvider module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2023-52362HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Permission management vulnerability in the lock screen module.Successful exploitation of this vulnerability may affect availability.

  • CVE-2023-37572HigDec 5, 2023
    risk 0.49cvss 7.5epss 0.01

    Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.

  • CVE-2023-43984HigNov 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download user information from the ps_customer table.

  • CVE-2023-42261HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication…

  • CVE-2023-5042HigSep 20, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713, Acronis True Image OEM (Windows) before build 42575.

  • CVE-2023-33966HigMay 31, 2023
    risk 0.49cvss 8.6epss 0.01

    Deno is a runtime for JavaScript and TypeScript. In deno 1.34.0 and deno_runtime 0.114.0, outbound HTTP requests made using the built-in `node:http` or `node:https` modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies…

  • CVE-2023-29731HigMay 30, 2023
    risk 0.49cvss 7.5epss 0.01

    SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application…

  • CVE-2023-1693HigMay 20, 2023
    risk 0.49cvss 7.5epss 0.00

    The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2022-45459HigMay 18, 2023
    risk 0.49cvss 7.5epss 0.00

    Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agent (Windows) before build 30025, Acronis Cyber Protect 15 (Windows) before build 30984.