CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,510 vulnerabilities with CWE-276
CVE-2024-34474 HIGH
Clario <2024-04-11 - Privilege Escalation
CVSS 7.8
CVE-2024-34455 HIGH
Buildroot <2024.02.2 - Info Disclosure
CVSS 7.5
CVE-2024-4226 LOW
Octopus Server 2022.2.6729-2022.2.7934 - Unauthenticated User Enumeration and Permission Exposure
CVSS 3.5
CVE-2024-34011 MEDIUM
Acronis Cyber Protect Cloud Agent (Windows) <37758 - Privilege Esca...
CVSS 6.8
CVE-2024-2859 MEDIUM
Brocade SANnav < 2.3.0 - Incorrect Default Permissions for Root Account
CVSS 6.8
CVE-2024-32368 HIGH
Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW 3.0 - Denial of Service via Bluetooth Low Energy Component
CVSS 7.3
CVE-2024-29967 MEDIUM
Brocade SANnav <2.31-2.3.0a - Info Disclosure
CVSS 4.4
CVE-2024-29962 MEDIUM
Brocade SANnav <2.3.1-2.3.0a - Info Disclosure
CVSS 5.5
CVE-2024-21116 HIGH
Oracle VM VirtualBox < 7.0.16 - Privilege Escalation via Incorrect Default Permissions
CVSS 7.8
CVE-2024-21012 LOW
Oracle GraalVM and JDK - Unauthenticated Data Manipulation via Networking Component
CVSS 3.7
CVE-2024-21004 LOW
Oracle GraalVM 20.3.13, 21.3.9 and Oracle Java SE 8u401 - Unauthenticated Incorrect Default Permissions in JavaFX
CVSS 2.5
CVE-2024-21002 LOW
Oracle GraalVM 20.3.13, 21.3.9 and Oracle Java SE 8u401 - Unauthenticated Incorrect Default Permissions in JavaFX
CVSS 2.5
CVE-2024-28056 CRITICAL
AWS Amplify CLI < 12.10.1 - Incorrect IAM Role Trust Policy Configuration
CVSS 9.8
CVE-2024-21615 MEDIUM
Junos OS and Junos OS Evolved - Information Disclosure via NETCONF Traceoptions
CVSS 5.0
CVE-2024-31442 HIGH
Redon Hub < 1.0.2 - Incorrect Default Permissions
CVSS 8.8
CVE-2024-26574 HIGH
Wondershare Filmora 13.0.51 - Local Privilege Escalation via WSNativePushService.exe
CVSS 7.8
CVE-2024-30415 CRITICAL
Huawei EMUI and HarmonyOS - Denial of Service via Window Management Module
CVSS 9.1
CVE-2024-30977 HIGH
Secnet Security Network Intelligent AC Management System <1.02.040 ...
CVSS 7.8
CVE-2024-27674 HIGH
Macro Expert <4.9.4 - Privilege Escalation
CVSS 7.8
CVE-2024-0259 HIGH
Fortra Robot Schedule Enterprise Agent for Windows < 3.04 - Privilege Escalation via Service Executable Overwrite
CVSS 7.3
CVE-2024-25958 MEDIUM
Dell Grab <= 5.0.4 - Authenticated Privilege Escalation via Weak Application Folder Permissions
CVSS 6.7
CVE-2024-30204 LOW
Emacs < 29.3 - Incorrect Default Permissions for LaTeX Preview in Email Attachments
CVSS 2.8
CVE-2024-22085 MEDIUM
Elspec G5 <1.1.4.15 - Info Disclosure
CVSS 6.2
CVE-2024-25654 MEDIUM
AVSystem Unified Management Platform 23.07.0.16567~LTS - Sensitive Information Exposure via Log File Permissions
CVSS 5.5
CVE-2024-1605 MEDIUM
BMC Control-M 9.0.20-9.0.20.237 and 9.0.21-9.0.21.200 - Unauthenticated DLL Hijacking via Insecure Directory Permissions
CVSS 6.6
Details
Vulnerabilities 1,510
Exploit Likelihood Medium