VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 59 of 79
  • CVE-2021-0979MedDec 15, 2021
    risk 0.36cvss 5.5epss 0.00

    In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass. This could lead to local information disclosure with no additional…

  • CVE-2021-3720MedNov 12, 2021
    risk 0.36cvss 5.5epss 0.00

    An information disclosure vulnerability was reported in the Time Weather system widget on Legion Phone Pro (L79031) and Legion Phone2 Pro (L70081) that could allow other applications to access device GPS data.

  • CVE-2021-38379MedOct 27, 2021
    risk 0.36cvss 5.5epss 0.00

    The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

  • CVE-2021-33923MedSep 29, 2021
    risk 0.36cvss 5.5epss 0.00

    Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access some sensitive information (private keys, state database).

  • CVE-2021-1832MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    Copied files may not have the expected file permissions. This issue is fixed in Security Update 2021-002 Catalina, iOS 14.5 and iPadOS 14.5, watchOS 7.4, tvOS 14.5, macOS Big Sur 11.3. The issue was addressed with improved permissions logic.

  • CVE-2021-1831MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. An application may allow shortcuts to access restricted files.

  • CVE-2021-30750MedSep 8, 2021
    risk 0.36cvss 5.5epss 0.01

    The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.3. A malicious application may be able to access the user's recent contacts.

  • CVE-2021-31007MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    Description: A permissions issue was addressed with improved validation. This issue is fixed in iOS 15.1 and iPadOS 15.1, tvOS 15.1, macOS Big Sur 11.6.2, watchOS 8.1, macOS Monterey 12.1. A malicious application may be able to bypass Privacy preferences.

  • CVE-2021-31006MedAug 24, 2021
    risk 0.36cvss 5.5epss 0.01

    Description: A permissions issue was addressed with improved validation. This issue is fixed in watchOS 7.6, tvOS 14.7, macOS Big Sur 11.5. A malicious application may be able to bypass certain Privacy preferences.

  • CVE-2021-22295MedAug 6, 2021
    risk 0.36cvss 5.5epss 0.00

    A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to cause the device to hang due to the page error OsVmPageFaultHandler.

  • CVE-2021-20490MedJun 29, 2021
    risk 0.36cvss 5.5epss 0.00

    IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure file permission settings. IBM X-Force ID: 197791.

  • CVE-2020-9451MedMay 25, 2021
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet…

  • CVE-2021-3451MedApr 27, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.

  • CVE-2021-30494MedApr 14, 2021
    risk 0.36cvss 5.5epss 0.01

    Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the Razer Chroma SDK subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log…

  • CVE-2021-30493MedApr 14, 2021
    risk 0.36cvss 5.5epss 0.01

    Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries within the ChromaBroadcast subkey. These privileged operations consist of file name concatenation of a runtime log file that is used to store runtime log…

  • CVE-2021-3462MedApr 13, 2021
    risk 0.36cvss 5.5epss 0.00

    A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.

  • CVE-2021-25381MedApr 9, 2021
    risk 0.36cvss 5.5epss 0.00

    Using unsafe PendingIntent in Samsung Account in versions 10.8.0.4 in Android P(9.0) and below, and 12.1.1.3 in Android Q(10.0) and above allows local attackers to perform unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-25355MedMar 25, 2021
    risk 0.36cvss 5.5epss 0.00

    Using unsafe PendingIntent in Samsung Notes prior to version 4.2.00.22 allows local attackers unauthorized action without permission via hijacking the PendingIntent.

  • CVE-2021-0381MedMar 10, 2021
    risk 0.36cvss 5.5epss 0.00

    In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-8357MedMar 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.