CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2021-44905 HIGH
Fortessa FTBTLD Smart Lock >=12-13-2022 - Unauthenticated Lock Disable via Bluetooth Lock Name Edit
CVSS 8.2
CVE-2021-44751 MEDIUM
F-Secure SAFE < 18.5 - Unauthenticated USSD Code Injection via Malicious Website
CVSS 4.3
CVE-2021-22571 MEDIUM
sa360_webquery_to_bigquery_exporter < 1.0.3 - Unauthenticated Local File Read via Temporary Report Staging
CVSS 5.5
CVE-2021-39694 HIGH
Android 12 - Local Privilege Escalation via RoleParser Permissions Bypass
CVSS 7.8
CVE-2021-44216 MEDIUM
CFEngine < 3.15.5 and 3.18.x < 3.18.1 - Unauthorized Local File Access via Insecure Log File Permissions
CVSS 5.5
CVE-2021-44215 MEDIUM
CFEngine < 3.15.5 - Insecure Default Permissions
CVSS 5.5
CVE-2021-40059 MEDIUM
Huawei EMUI and Magic UI - Incorrect Default Permissions in Wi-Fi Module
CVSS 6.5
CVE-2021-40053 CRITICAL
Huawei EMUI - Incorrect Default Permissions in Nearby Module
CVSS 9.1
CVE-2021-40049 HIGH
Huawei EMUI - Unauthorized Sensitive Information Disclosure via PMS Module
CVSS 7.5
CVE-2021-3981 LOW
GRUB2 < 2.06 - Unprotected Configuration File Permissions
CVSS 3.3
CVE-2021-32006 MEDIUM
Secomea GateManager <9.6.621421014 - Privilege Escalation
CVSS 5.0
CVE-2021-20269 MEDIUM
kexec-tools < 2.0.21-8 - Unauthenticated Kernel Information Leak via Log File Permissions
CVSS 5.5
CVE-2021-38268 MEDIUM
Liferay Portal/DXP <7.4 - Privilege Escalation
CVSS 6.5
CVE-2021-41652 HIGH
BatFlat CMS 1.3.6 - Insecure Default Permissions in Database File
CVSS 7.5
CVE-2021-37103 MEDIUM
Huawei EMUI and Magic UI - Incorrect Default Permissions in Wallet Apps
CVSS 5.5
CVE-2021-45083 HIGH
Cobbler < 3.3.1 - Unauthenticated Sensitive Information Exposure via World-Readable Configuration Files
CVSS 7.1
CVE-2021-3948 MEDIUM
mig-controller - Incorrect Default Permissions via Cluster Namespace Handling
CVSS 6.3
CVE-2021-3155 LOW
snapd < 2.54.3 - Unprotected User Data Exposure via Home Directory Permissions
CVSS 3.8
CVE-2021-20001 CRITICAL
debian-edu-config < 2.12.16 - Incorrect Default Permissions for User Web Shares
CVSS 9.8
CVE-2021-39658 CRITICAL
Android - Incorrect Default Permissions in ismsEx Service
CVSS 9.8
CVE-2021-39635 CRITICAL
Android - Unauthenticated VoLTE Information Disclosure and Call Management via ims_ex Service
CVSS 9.1
CVE-2021-33166 MEDIUM
Intel(R) RXT for Chromebook - Info Disclosure
CVSS 5.5
CVE-2021-33129 HIGH
Intel(R) Advisor <2021.4.0 - Privilege Escalation
CVSS 7.8
CVE-2021-22817 HIGH
Harmony/Magelis iPC Series - Privilege Escalation
CVSS 7.8
CVE-2021-0093 MEDIUM
Intel Atom and Core i3 Processors - Denial of Service via Incorrect Firmware Permissions
CVSS 4.4
Details
Vulnerabilities 1,512
Exploit Likelihood Medium