VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 5 of 79
  • CVE-2021-27193CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.01

    Incorrect default permissions vulnerability in the API of Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to read and write files on the remote machine with system privileges resulting in a privilege escalation.

  • CVE-2019-20468CriFeb 1, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS.

  • CVE-2020-13452CriJan 7, 2021
    risk 0.64cvss 9.8epss 0.03

    In Gotenberg through 6.2.1, insecure permissions for tini (writable by user gotenberg) potentially allow an attacker to overwrite the file, which can lead to denial of service or code execution.

  • CVE-2020-10279CriJun 24, 2020
    risk 0.64cvss 9.8epss 0.01

    MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate their access beyond what they were…

  • CVE-2020-11716CriMay 20, 2020
    risk 0.64cvss 9.8epss 0.01

    Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."

  • CVE-2020-9409CriMay 20, 2020
    risk 0.64cvss 9.8epss 0.03

    The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an unauthenticated attacker to obtain the…

  • CVE-2019-20536CriMar 24, 2020
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).

  • CVE-2020-9039CriFeb 22, 2020
    risk 0.64cvss 9.8epss 0.04

    Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint exposed by the projector process is an…

  • CVE-2020-8114CriFeb 5, 2020
    risk 0.64cvss 9.8epss 0.01

    GitLab EE 8.9 and later through 12.7.2 has Insecure Permission

  • CVE-2019-19392CriJan 21, 2020
    risk 0.64cvss 9.8epss 0.01

    The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.

  • CVE-2017-16128CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.01

    The module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.

  • CVE-2017-16127CriJun 7, 2018
    risk 0.64cvss 9.8epss 0.01

    The module pandora-doomsday infects other modules. It's since been unpublished from the registry.

  • CVE-2017-0847CriNov 16, 2017
    risk 0.64cvss 9.8epss 0.00

    An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.

  • CVE-2017-5642CriApr 3, 2017
    risk 0.64cvss 9.8epss 0.02

    During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.

  • CVE-2020-6471CriMay 21, 2020
    risk 0.63cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-6469CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2021-3394HigFeb 9, 2021
    risk 0.61cvss 8.8epss 0.06

    Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder permissions allowing a malicious user for a local privilege escalation.

  • CVE-2017-12763HigAug 29, 2017
    risk 0.61cvss 8.8epss 0.04

    An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privileges by gaining access to local files.

  • CVE-2006-5014HigSep 27, 2006
    risk 0.61cvss 8.8epss 0.04

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.

  • CVE-2023-4088CriSep 20, 2023
    risk 0.60cvss 9.3epss 0.00

    Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS)…