CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,487 vulnerabilities with CWE-276
CVE-2025-15336 MEDIUM
Tanium Performance < 1.17.134 - Incorrect Default Permissions
CVSS 6.5
CVE-2025-15335 MEDIUM
Tanium Threat Response < 4.5.266 - Incorrect Default Permissions
CVSS 4.3
CVE-2025-15334 MEDIUM
Tanium Threat Response < 4.5.266 - Incorrect Default Permissions
CVSS 4.3
CVE-2025-15333 MEDIUM
Tanium Threat Response < 4.5.266 - Incorrect Default Permissions
CVSS 4.3
CVE-2025-10314 HIGH
Mitsubishi Electric FREQSHIP-mini <8.0.2 - Code Injection
CVSS 8.8
CVE-2025-69604 HIGH
Shirt-pocket Superduper! < 3.12 - Incorrect Default Permissions
CVSS 7.8
CVE-2025-13905 HIGH
CWE-276 - Privilege Escalation
CVE-2025-67230 HIGH
Todesktop Builder < 0.33.0 - Incorrect Default Permissions
CVSS 7.1
CVE-2025-15523 MEDIUM
Inkscape - Code Injection
CVE-2025-55132 MEDIUM
Node.js - Info Disclosure
CVSS 5.3
CVE-2025-67813 MEDIUM
Quest Kace Desktop Authority < 11.3.2 - Incorrect Default Permissions
CVSS 5.3
CVE-2025-60262 CRITICAL
H3C Mc102-g Firmware - Incorrect Default Permissions
CVSS 9.8
CVE-2025-64724 HIGH
Arduino IDE <2.3.7 - Privilege Escalation
CVSS 7.3
CVE-2025-64723 MEDIUM
Arduino IDE <2.3.7 - Code Injection
CVSS 4.4
CVE-2025-53919 HIGH
Dell Color Management <3.3.008 - Privilege Escalation
CVSS 7.8
CVE-2025-53398 HIGH
Dell Color Management <3.3.8 - Info Disclosure
CVSS 7.8
CVE-2025-43519 MEDIUM
macOS - Info Disclosure
CVSS 5.5
CVE-2025-13155 HIGH
Lenovo Baiying Client - Privilege Escalation
CVSS 7.8
CVE-2025-59030 HIGH
Product <Version - DoS
CVSS 7.5
CVE-2025-57850 MEDIUM
CodeReady Workspaces - Privilege Escalation
CVSS 6.4
CVE-2025-61229 HIGH
Shirt Pocket's SuperDuper! <3.10 - Privilege Escalation
CVSS 7.8
CVE-2025-59485 LOW
MaLion <5.3.4 - Privilege Escalation
CVSS 3.3
CVE-2025-54866 MEDIUM
Wazuh < 4.13.0 - Incorrect Default Permissions
CVSS 5.5
CVE-2025-58097 HIGH
Secuavail Logstare Collector < 2.4.2 - Incorrect Default Permissions
CVSS 7.8
CVE-2025-34333 HIGH
Audiocodes Fax Server < 2.6.23 - Incorrect Default Permissions
CVSS 7.8
Details
Vulnerabilities 1,487
Exploit Likelihood Medium