CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 35 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44858 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead. | ||
| CVE-2021-37030 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-22368 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device. | ||
| CVE-2021-22371 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-21737 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2021 | A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10… | ||
| CVE-2020-21342 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2021 | Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php. | ||
| CVE-2020-27569 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2021 | Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system. | ||
| CVE-2020-23971 | Hig | 0.49 | 7.5 | 0.02 | Sep 1, 2020 | gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the… | ||
| CVE-2020-2077 | Hig | 0.49 | 7.5 | 0.01 | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly. | ||
| CVE-2019-9943 | Hig | 0.49 | 7.5 | 0.01 | Jun 17, 2020 | In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled. | ||
| CVE-2020-13894 | Hig | 0.49 | 7.5 | 0.01 | Jun 7, 2020 | handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field. | ||
| CVE-2017-18669 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017). | ||
| CVE-2017-18668 | Hig | 0.49 | 7.5 | 0.00 | Apr 7, 2020 | An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017). | ||
| CVE-2019-3944 | Hig | 0.49 | 7.5 | 0.02 | Apr 1, 2020 | Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight. | ||
| CVE-2020-7943 | Hig | 0.49 | 7.5 | 0.08 | Mar 11, 2020 | Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as… | ||
| CVE-2020-7972 | Hig | 0.49 | 7.5 | 0.01 | Feb 5, 2020 | GitLab EE 12.2 has Insecure Permissions (issue 2 of 2). | ||
| CVE-2010-5108 | Hig | 0.49 | 7.5 | 0.01 | Nov 13, 2019 | Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions. | ||
| CVE-2012-5577 | Hig | 0.49 | 7.5 | 0.02 | Oct 28, 2019 | Python keyring lib before 0.10 created keyring files with world-readable permissions. | ||
| CVE-2019-16106 | Hig | 0.49 | 7.5 | 0.01 | Sep 10, 2019 | The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields. | ||
| CVE-2019-9630 | Hig | 0.49 | 7.5 | 0.01 | Jul 8, 2019 | Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images. |
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
- risk 0.49cvss 7.5epss 0.01
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.
- risk 0.49cvss 7.5epss 0.01
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10…
- risk 0.49cvss 7.5epss 0.01
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
- risk 0.49cvss 7.5epss 0.01
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
- risk 0.49cvss 7.5epss 0.02
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the…
- risk 0.49cvss 7.5epss 0.01
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.
- risk 0.49cvss 7.5epss 0.01
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model objects may be circumvented during certain operations such as move and delete, because group permissions are mishandled.
- risk 0.49cvss 7.5epss 0.01
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launch of any activity with system privileges. The Samsung ID is SVE-2017-9000 (June 2017).
- risk 0.49cvss 7.5epss 0.00
An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound calls and sending outbound text messages. The Samsung ID is SVE-2017-8706 (June 2017).
- risk 0.49cvss 7.5epss 0.02
Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect drone from controller during mid-flight.
- risk 0.49cvss 7.5epss 0.08
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as…
- risk 0.49cvss 7.5epss 0.01
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- risk 0.49cvss 7.5epss 0.01
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
- risk 0.49cvss 7.5epss 0.02
Python keyring lib before 0.10 created keyring files with world-readable permissions.
- risk 0.49cvss 7.5epss 0.01
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
- risk 0.49cvss 7.5epss 0.01
Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.