VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 57 of 79
  • CVE-2023-29081MedJan 26, 2024
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders.

  • CVE-2022-4964MedJan 24, 2024
    risk 0.36cvss 5.5epss 0.00

    Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.

  • CVE-2022-45793MedJan 10, 2024
    risk 0.36cvss 5.5epss 0.00

    Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker to overwrite files which will result in code execution with privileges of a different user.

  • CVE-2023-40076MedDec 4, 2023
    risk 0.36cvss 5.5epss 0.02

    In createPendingIntent of CredentialManagerUi.java, there is a possible way to access credentials from other users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-4065MedSep 27, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in Red Hat AMQ Broker Operator, where it displayed a password defined in ActiveMQArtemisAddress CR, shown in plain text in the Operator Log. This flaw allows an authenticated local attacker to access information outside of their permissions.

  • CVE-2023-30902MedJun 26, 2023
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations.

  • CVE-2023-32407MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.01

    A logic issue was addressed with improved state management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, macOS Big Sur 11.7.7, macOS Monterey 12.6.6, iOS 16.5 and iPadOS 16.5. An app may be able to bypass Privacy preferences.

  • CVE-2023-32404MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    This issue was addressed with improved entitlements. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.

  • CVE-2023-32399MedJun 23, 2023
    risk 0.36cvss 5.5epss 0.00

    The issue was addressed with improved handling of caches. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to read sensitive location information.

  • CVE-2023-21104MedMay 15, 2023
    risk 0.36cvss 5.5epss 0.00

    In applySyncTransaction of WindowOrganizer.java, a missing permission check could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID:…

  • CVE-2023-28192MedMay 8, 2023
    risk 0.36cvss 5.5epss 0.00

    A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. An app may be able to read sensitive location information.

  • CVE-2022-3146MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to…

  • CVE-2022-3101MedMar 23, 2023
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to…

  • CVE-2022-1109MedJan 20, 2023
    risk 0.36cvss 5.5epss 0.00

    An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.

  • CVE-2022-20448MedNov 8, 2022
    risk 0.36cvss 5.5epss 0.00

    In buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2013-4281MedOct 19, 2022
    risk 0.36cvss 5.5epss 0.00

    In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.

  • CVE-2021-46834MedSep 20, 2022
    risk 0.36cvss 5.5epss 0.00

    A permission bypass vulnerability in Huawei cross device task management could allow an attacker to access certain resource in the attacked devices. Affected product versions include:JAD-AL50 versions 102.0.0.225(C00E220R3P4).

  • CVE-2022-27500MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2021-44470MedAug 18, 2022
    risk 0.36cvss 5.5epss 0.00

    Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2022-20272MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PermissionController, there is a possible misunderstanding about the default SMS application's permission set due to misleading text. This could lead to local information disclosure with User privileges needed. User interaction is needed for exploitation.Product:…