VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,581)

page 62 of 80
  • CVE-2020-0294MedSep 18, 2020
    risk 0.36cvss 5.5epss 0.00

    In bindWallpaperComponentLocked of WallpaperManagerService.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0390MedSep 17, 2020
    risk 0.36cvss 5.5epss 0.00

    In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID:…

  • CVE-2020-8346MedSep 15, 2020
    risk 0.36cvss 5.5epss 0.00

    A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.

  • CVE-2020-15578MedJul 7, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).

  • CVE-2020-13867MedJun 5, 2020
    risk 0.36cvss 5.5epss 0.00

    Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).

  • CVE-2020-8798MedApr 23, 2020
    risk 0.36cvss 5.5epss 0.00

    httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.

  • CVE-2019-8731MedDec 18, 2019
    risk 0.36cvss 5.5epss 0.01

    A permissions issue existed in which execute permission was incorrectly granted. This issue was addressed with improved permission validation. This issue is fixed in iOS 13. Processing a maliciously crafted file may disclose user information.

  • CVE-2019-19460MedDec 3, 2019
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-2019-19458 or CVE-2019-19459 is…

  • CVE-2012-6136MedNov 20, 2019
    risk 0.36cvss 5.5epss 0.00

    tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.

  • CVE-2019-15716MedAug 28, 2019
    risk 0.36cvss 5.5epss 0.00

    WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or were based on unsafe OS defaults.

  • CVE-2018-7822MedMay 22, 2019
    risk 0.36cvss 5.5epss 0.00

    An Incorrect Default Permissions (CWE-276) vulnerability exists in SoMachine Basic, all versions, and Modicon M221(all references, all versions prior to firmware V1.10.0.0) which could cause unauthorized access to SoMachine Basic resource files when logged on the system hosting…

  • CVE-2017-7761MedJun 11, 2018
    risk 0.36cvss 5.5epss 0.00

    The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the…

  • CVE-2018-0023MedApr 11, 2018
    risk 0.36cvss 5.5epss 0.00

    JSNAPy is an open source python version of Junos Snapshot Administrator developed by Juniper available through github. The default configuration and sample files of JSNAPy automation tool versions prior to 1.3.0 are created world writable. This insecure file and directory…

  • CVE-2017-6404MedMar 2, 2017
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Veritas NetBackup Before 7.7 and NetBackup Appliance Before 2.7. There are world-writable log files, allowing destruction or spoofing of log data.

  • CVE-2002-1713MedDec 31, 2002
    risk 0.36cvss 5.5epss 0.00

    The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.

  • CVE-2026-20718MedMay 12, 2026
    risk 0.35cvss —epss 0.00

    Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack…

  • CVE-2024-57438MedJan 29, 2025
    risk 0.35cvss 5.4epss 0.00

    Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.

  • CVE-2024-8037MedOct 2, 2024
    risk 0.35cvss 6.5epss 0.00

    Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the local system with access to the default network namespace may connect to the @/var/lib/juju/agents/unit-xxxx-yyyy/agent.socket and perform actions that are…

  • CVE-2024-21122MedJul 16, 2024
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2023-38335MedJul 20, 2023
    risk 0.35cvss 5.3epss 0.01

    Omnis Studio 10.22.00 has incorrect access control. It advertises a feature for making Omnis libraries "always private" - this is supposed to be an irreversible operation. However, due to implementation issues, "always private" Omnis libraries can be opened by the Omnis Studio…