CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,510 vulnerabilities with CWE-276
CVE-2024-6238 HIGH
pgAdmin <=8.8 - Privilege Escalation
CVSS 7.4
CVE-2024-22385 MEDIUM
Hitachi Storage Provider - Info Disclosure
CVSS 4.4
CVE-2024-36495 HIGH
Faronics WINSelect - Info Disclosure
CVSS 7.7
CVE-2024-5967 LOW
Keycloak LDAP Federation >=25.0.0 <25.0.1 - Authenticated Credential Leak via LDAP Connection URL Change
CVSS 2.7
CVE-2024-38459 HIGH
langchain_experimental <0.0.61 - RCE
CVSS 7.8
CVE-2024-34012 MEDIUM
Acronis Cloud Manager <6.2.24135.272 - Privilege Escalation
CVSS 4.4
CVE-2024-27180 MEDIUM
Rogue App Installation - Privilege Escalation
CVSS 6.7
CVE-2024-27171 HIGH
Toshiba Tec e-Studio MFP - Python File Overwrite Remote Code Execution
CVSS 7.4
CVE-2024-27167 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Local Privilege Escalation via Sendmail Configuration Injection
CVSS 7.4
CVE-2024-27166 HIGH
Toshiba Tec e-Studio multi-function peripheral (MFP) - Plaintext Password Exposure via Coredump Permissions
CVSS 7.4
CVE-2024-27155 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.7
CVE-2024-27153 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27152 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27151 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27150 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27149 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27148 HIGH
Toshiba Printers - Privilege Escalation
CVSS 7.4
CVE-2024-27144 CRITICAL
Toshiba Printers - Privilege Escalation
CVSS 9.8
CVE-2024-37038 HIGH
Schneider Electric SAGE RTU < c3414-500-s02k5_p9 - Authenticated Unauthorized File/Firmware Upload
CVSS 7.5
CVE-2024-23847 MEDIUM
Yokogawa Unifier - Incorrect Default Permissions Code Execution as LocalSystem
CVSS 5.9
CVE-2024-32978 MEDIUM
Kaminari 0.15.0-0.16.1 - Insecure File Permissions
CVSS 6.6
CVE-2024-27264 HIGH
IBM Performance Tools for i <7.6 - Privilege Escalation
CVSS 7.4
CVE-2024-34223 MEDIUM
SourceCodester HRMS 1.0 - Info Disclosure
CVSS 4.3
CVE-2024-34221 HIGH
Sourcecodester HRMS 1.0 - Privilege Escalation
CVSS 8.8
CVE-2024-4030 HIGH
CPython < 3.8.20, 3.9.0-3.9.19, 3.10.0-3.10.14, 3.11.0-3.11.9, 3.12.0-3.12.3, 3.13.0a1 - Incorrect Default Permissions
CVSS 7.1
Details
Vulnerabilities 1,510
Exploit Likelihood Medium