CWE-276
Incorrect Default Permissions
Description
During installation, installed file permissions are set to allow anyone to modify those files.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-1 · CAPEC-127 · CAPEC-81
CVEs mapped to this weakness (1,561)
page 57 of 79| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-29081 | Med | 0.36 | 5.5 | 0.00 | Jan 26, 2024 | A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders. | ||
| CVE-2022-4964 | Med | 0.36 | 5.5 | 0.00 | Jan 24, 2024 | Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set. | ||
| CVE-2022-45793 | Med | 0.36 | 5.5 | 0.00 | Jan 10, 2024 | Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user. | ||
| CVE-2023-40076 | Med | 0.36 | 5.5 | 0.02 | Dec 4, 2023 | In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-4065 | Med | 0.36 | 5.5 | 0.00 | Sep 27, 2023 | A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions. | ||
| CVE-2023-30902 | Med | 0.36 | 5.5 | 0.00 | Jun 26, 2023 | A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations. | ||
| CVE-2023-32407 | Med | 0.36 | 5.5 | 0.01 | Jun 23, 2023 | A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences. | ||
| CVE-2023-32404 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2023 | This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences. | ||
| CVE-2023-32399 | Med | 0.36 | 5.5 | 0.00 | Jun 23, 2023 | The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information. | ||
| CVE-2023-21104 | Med | 0.36 | 5.5 | 0.00 | May 15, 2023 | In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:… | ||
| CVE-2023-28192 | Med | 0.36 | 5.5 | 0.00 | May 8, 2023 | A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information. | ||
| CVE-2022-3146 | Med | 0.36 | 5.5 | 0.00 | Mar 23, 2023 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to… | ||
| CVE-2022-3101 | Med | 0.36 | 5.5 | 0.00 | Mar 23, 2023 | A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to… | ||
| CVE-2022-1109 | Med | 0.36 | 5.5 | 0.00 | Jan 20, 2023 | An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service. | ||
| CVE-2022-20448 | Med | 0.36 | 5.5 | 0.00 | Nov 8, 2022 | In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2013-4281 | Med | 0.36 | 5.5 | 0.00 | Oct 19, 2022 | In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file. | ||
| CVE-2021-46834 | Med | 0.36 | 5.5 | 0.00 | Sep 20, 2022 | A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4). | ||
| CVE-2022-27500 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2021-44470 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2022 | Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access. | ||
| CVE-2022-20272 | Med | 0.36 | 5.5 | 0.00 | Aug 12, 2022 | In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product:… |
- risk 0.36cvss 5.5epss 0.00
A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.
- risk 0.36cvss 5.5epss 0.00
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
- risk 0.36cvss 5.5epss 0.00
Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.
- risk 0.36cvss 5.5epss 0.02
In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.
- risk 0.36cvss 5.5epss 0.00
A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations.
- risk 0.36cvss 5.5epss 0.01
A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.
- risk 0.36cvss 5.5epss 0.00
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information.
- risk 0.36cvss 5.5epss 0.00
In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:…
- risk 0.36cvss 5.5epss 0.00
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information.
- risk 0.36cvss 5.5epss 0.00
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to…
- risk 0.36cvss 5.5epss 0.00
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
- risk 0.36cvss 5.5epss 0.00
In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
- risk 0.36cvss 5.5epss 0.00
A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).
- risk 0.36cvss 5.5epss 0.00
Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.
- risk 0.36cvss 5.5epss 0.00
In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product:…