VYPR

CWE-276

Incorrect Default Permissions

BaseDraftLikelihood: Medium

Description

During installation, installed file permissions are set to allow anyone to modify those files.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-1 · CAPEC-127 · CAPEC-81

CVEs mapped to this weakness (1,561)

page 64 of 79
  • CVE-2024-20830MedMar 5, 2024
    risk 0.34cvss 5.3epss 0.00

    Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.

  • CVE-2024-22301MedJan 24, 2024
    risk 0.34cvss 5.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This issue affects Albo Pretorio On line: from n/a through 4.6.6.

  • CVE-2023-6273MedDec 6, 2023
    risk 0.34cvss 5.3epss 0.00

    Permission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause features to perform abnormally.

  • CVE-2023-34352MedSep 6, 2023
    risk 0.34cvss 5.3epss 0.01

    A permissions issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.4, tvOS 16.5, iOS 16.5 and iPadOS 16.5, watchOS 9.5. An attacker may be able to leak user account emails.

  • CVE-2023-32492MedAug 16, 2023
    risk 0.34cvss 5.3epss 0.00

    Dell PowerScale OneFS 9.5.0.x contains an incorrect default permissions vulnerability. A low-privileged local attacker could potentially exploit this vulnerability, leading to information disclosure or allowing to modify files.

  • CVE-2021-36400MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.

  • CVE-2021-36397MedMar 6, 2023
    risk 0.34cvss 5.3epss 0.01

    In Moodle, insufficient capability checks meant message deletions were not limited to the current user.

  • CVE-2021-46811MedJun 13, 2022
    risk 0.34cvss 5.3epss 0.00

    HwSEServiceAPP has a vulnerability in permission management. Successful exploitation of this vulnerability may cause disclosure of the Card Production Life Cycle (CPLC) information.

  • CVE-2022-27652MedApr 18, 2022
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker…

  • CVE-2021-37132MedJan 3, 2022
    risk 0.34cvss 5.3epss 0.01

    PackageManagerService has a Permissions, Privileges, and Access Controls vulnerability .Successful exploitation of this vulnerability may cause that Third-party apps can obtain the complete list of Harmony apps without permission.

  • CVE-2021-22475MedOct 28, 2021
    risk 0.34cvss 5.3epss 0.01

    There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-22346MedJun 30, 2021
    risk 0.34cvss 5.3epss 0.01

    There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may lead to the disclosure of user habits.

  • CVE-2021-22538MedMar 31, 2021
    risk 0.34cvss 6.3epss 0.01

    A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with…

  • CVE-2020-8024MedJun 29, 2020
    risk 0.34cvss 5.3epss 0.00

    A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions…

  • CVE-2018-12160MedSep 12, 2018
    risk 0.34cvss 5.3epss 0.00

    DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using default directory permissions via local access.

  • CVE-2026-28717MedMar 6, 2026
    risk 0.33cvss 5.0epss 0.00

    Local privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) before build 41186.

  • CVE-2025-22425MedSep 4, 2025
    risk 0.33cvss 5.1epss 0.00

    In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

  • CVE-2025-46803MedMay 26, 2025
    risk 0.33cvss 5.0epss 0.00

    The default mode of pseudo terminals (PTYs) allocated by Screen was changed from 0620 to 0622, thereby allowing anyone to write to any Screen PTYs in the system.

  • CVE-2025-46586MedMay 6, 2025
    risk 0.33cvss 5.1epss 0.00

    Permission control vulnerability in the contacts module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-58049MedMar 4, 2025
    risk 0.33cvss 5.0epss 0.00

    Permission verification vulnerability in the media library module Impact: Successful exploitation of this vulnerability may affect service confidentiality.