CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,581)
page 35 of 80| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-32743 | Hig | 0.49 | 7.5 | 0.01 | Sep 1, 2022 | Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it. | ||
| CVE-2022-37006 | Hig | 0.49 | 7.5 | 0.01 | Aug 10, 2022 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2022-33023 | Hig | 0.49 | 7.5 | 0.01 | Jun 29, 2022 | CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong. | ||
| CVE-2022-23802 | Hig | 0.49 | 7.5 | 0.01 | May 6, 2022 | Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private… | ||
| CVE-2022-29585 | Hig | 0.49 | 7.5 | 0.01 | Apr 28, 2022 | In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of). | ||
| CVE-2022-29547 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2022 | The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page. | ||
| CVE-2021-40049 | Hig | 0.49 | 7.5 | 0.01 | Mar 10, 2022 | There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization. | ||
| CVE-2021-41652 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2022 | Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. | ||
| CVE-2021-46086 | Hig | 0.49 | 7.5 | 0.01 | Jan 25, 2022 | xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in… | ||
| CVE-2021-40004 | Hig | 0.49 | 7.5 | 0.01 | Jan 10, 2022 | The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-39967 | Hig | 0.49 | 7.5 | 0.01 | Jan 3, 2022 | There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-44858 | Hig | 0.49 | 7.5 | 0.01 | Dec 20, 2021 | An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead. | ||
| CVE-2021-37030 | Hig | 0.49 | 7.5 | 0.01 | Nov 23, 2021 | There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability. | ||
| CVE-2021-22368 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device. | ||
| CVE-2021-22371 | Hig | 0.49 | 7.5 | 0.01 | Jun 30, 2021 | There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-21737 | Hig | 0.49 | 7.5 | 0.01 | Jun 24, 2021 | A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10… | ||
| CVE-2020-21342 | Hig | 0.49 | 7.5 | 0.01 | May 13, 2021 | Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php. | ||
| CVE-2020-27569 | Hig | 0.49 | 7.5 | 0.01 | Apr 21, 2021 | Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system. | ||
| CVE-2020-23971 | Hig | 0.49 | 7.5 | 0.02 | Sep 1, 2020 | gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the… | ||
| CVE-2020-2077 | Hig | 0.49 | 7.5 | 0.01 | Jul 29, 2020 | SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly. |
- risk 0.49cvss 7.5epss 0.01
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it.
- risk 0.49cvss 7.5epss 0.01
Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
- risk 0.49cvss 7.5epss 0.01
Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. The impact is: obtain sensitive information (remote). The component is: Access to private information and components, possibility to view other users' information. Information disclosure Access to private…
- risk 0.49cvss 7.5epss 0.01
In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. They are all shown from page 2 of the group results list (rather than only being shown for the institution that the viewer is a member of).
- risk 0.49cvss 7.5epss 0.01
The CreateRedirect extension before 2022-04-14 for MediaWiki does not properly check whether the user has permissions to edit the target page. This could lead to an unauthorised (or blocked) user being able to edit a page.
- risk 0.49cvss 7.5epss 0.01
There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to sensitive system information being obtained without authorization.
- risk 0.49cvss 7.5epss 0.01
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
- risk 0.49cvss 7.5epss 0.01
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in…
- risk 0.49cvss 7.5epss 0.01
The cellular module has a vulnerability in permission management. Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.
- risk 0.49cvss 7.5epss 0.01
There is an Improper permission vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- risk 0.49cvss 7.5epss 0.01
There is a Permission Control Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect normal use of the device.
- risk 0.49cvss 7.5epss 0.01
There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
A smart STB product of ZTE is impacted by a permission and access control vulnerability. Due to insufficient protection of system application, attackers could use this vulnerability to tamper with the system desktop and affect system customization functions. This affects: ZXV10…
- risk 0.49cvss 7.5epss 0.01
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
- risk 0.49cvss 7.5epss 0.01
Arbitrary File Write exists in Aviatrix VPN Client 2.8.2 and earlier. The VPN service writes logs to a location that is world writable and can be leveraged to gain write access to any file on the system.
- risk 0.49cvss 7.5epss 0.02
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload function without authenticating to the application and also can upload files due the issues of unrestricted file uploads which can be bypassed by changing the…
- risk 0.49cvss 7.5epss 0.01
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings. An unauthorized attacker could read sensitive data from the system by querying for known files using the REST API directly.