CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,510 vulnerabilities with CWE-276
CVE-2024-28862 MEDIUM
rotp 6.2.1-6.2.9 - Incorrect Default Permissions
CVSS 5.3
CVE-2024-20671 MEDIUM
Microsoft Defender < - Privilege Escalation
CVSS 5.5
CVE-2024-23295 MEDIUM
visionOS < 1.1 - Unauthenticated Unprotected Persona Access
CVSS 5.5
CVE-2024-23253 LOW
macOS < 14.4 - Unprotected User Data Exposure via Photos Library Permissions
CVSS 3.3
CVE-2024-23201 MEDIUM
iPadOS < 17.3 - Denial of Service via Permissions Issue
CVSS 5.5
CVE-2024-22889 HIGH
Plone 6.0.9 - Unauthenticated Arbitrary File Read via Crafted Request
CVSS 7.5
CVE-2024-20841 MEDIUM
Samsung Account <14.8.00.3 - Privilege Escalation
CVSS 5.1
CVE-2024-20830 MEDIUM
AppLock <SMR MAr-2024 Release 1 - Privilege Escalation
CVSS 5.3
CVE-2024-20005 HIGH
Android - Local Privilege Escalation via Missing Permission Check
CVSS 8.2
CVE-2024-26280 MEDIUM
Apache Airflow < 2.8.2 - Authenticated Information Disclosure via Audit Log Permissions
CVSS 4.7
CVE-2024-26302 MEDIUM
ClearPass Policy Manager - Authenticated Information Disclosure via Web Management Interface
CVSS 4.8
CVE-2024-1156 HIGH
Emerson Data Record AD < 2.0.1 - Authenticated Privilege Escalation via RabbitMQ Configuration
CVSS 7.8
CVE-2024-1155 HIGH
SystemLink Elixir - Privilege Escalation
CVSS 7.8
CVE-2024-25605 MEDIUM
Liferay Portal <7.4.3.4 - Info Disclosure
CVSS 5.3
CVE-2024-20921 MEDIUM
Oracle GraalVM and JDK - Unauthenticated Unauthorized Data Access via Hotspot Component
CVSS 5.9
CVE-2024-0034 HIGH
Android - Local Privilege Escalation via Background Activity Launch Bypass
CVSS 7.8
CVE-2024-1488 HIGH
Unbound < 1.19.1-2.fc40 - Unauthenticated Configuration Manipulation via Localhost Port 8953
CVSS 8.0
CVE-2024-24828 MEDIUM
vercel/pkg < 5.8.1 - Unauthenticated Arbitrary Code Execution via Predictable /tmp/pkg/ Directory
CVSS 6.6
CVE-2024-22430 MEDIUM
Dell PowerScale OneFS 8.2.0-9.6.0 - Denial of Service via Incorrect Default Permissions
CVSS 5.5
CVE-2024-0833 HIGH
Telerik Test Studio <v2023.3.1330 - Privilege Escalation
CVSS 7.8
CVE-2024-21840 HIGH
Hitachi Storage Plug-in for VMware vCenter 04.0.0-04.9.2 - Incorrect Default Permissions
CVSS 7.9
CVE-2024-22301 MEDIUM
Albo Pretorio On line <4.6.6 - Info Disclosure
CVSS 5.3
CVE-2024-0770 MEDIUM
European Chemicals Agency IUCLID 7.10.3 - Info Disclosure
CVSS 4.4
CVE-2024-22409 HIGH
DataHub < 0.12.1 - Privilege Escalation via Default Permission Misconfiguration
CVSS 7.5
CVE-2024-22428 HIGH
Dell iDRAC Service Module <5.2.0.0 - Privilege Escalation
CVSS 7.0
Details
Vulnerabilities 1,510
Exploit Likelihood Medium