CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2021-46093 CRITICAL
eliteCMS v1.0 - Privilege Escalation
CVSS 9.8
CVE-2021-40416 HIGH
Reolink RLC-410W <3.0.0.136_20121102 - Info Disclosure
CVSS 8.8
CVE-2021-40415 MEDIUM
reolink RLC-410W v3.0.0.136_20121102 - Info Disclosure
CVSS 6.5
CVE-2021-40414 HIGH
reolink RLC-410W v3.0.0.136_20121102 - Info Disclosure
CVSS 7.1
CVE-2021-40413 HIGH
reolink RLC-410W v3.0.0.136_20121102 - Info Disclosure
CVSS 7.1
CVE-2021-40397 HIGH
Advantech WISE-PaaS/OTA Server <3.0.9 - Privilege Escalation
CVSS 7.8
CVE-2021-40396 HIGH
Advantech DeviceOn/iService <1.1.7 - Privilege Escalation
CVSS 8.8
CVE-2021-40389 HIGH
Advantech DeviceOn/iEdge Server <1.0.2 - Privilege Escalation
CVSS 8.8
CVE-2021-40388 HIGH
Advantech SQ Manager Server <1.0.6 - Privilege Escalation
CVSS 8.8
CVE-2021-41166 MEDIUM
Nextcloud Android <3.17.1 - Info Disclosure
CVSS 4.3
CVE-2021-46086 HIGH
xzs-mysql >= t3.4.0 - Info Disclosure
CVSS 7.5
CVE-2021-46085 MEDIUM
OneBlog <= 2.2.8 - Privilege Escalation
CVSS 6.5
CVE-2021-36781 MEDIUM
openSUSE Factory parsec < 0.8.1-1.1 - Incorrect Default Permissions
CVSS 5.9
CVE-2021-43860 HIGH
Flatpak <1.12.3-1.10.6 - Privilege Escalation
CVSS 8.2
CVE-2021-45003 CRITICAL
Laundry Booking Management System 1.0 - Remote Code Execution via Profile Image Parameter
CVSS 9.8
CVE-2021-40004 HIGH
HarmonyOS < 2.0 - Incorrect Default Permissions in Cellular Module
CVSS 7.5
CVE-2021-39967 HIGH
Huawei EMUI - Broadcast Information Disclosure via Improper Permission Settings
CVSS 7.5
CVE-2021-37132 MEDIUM
HarmonyOS < 2.0 - Unauthorized App List Disclosure via PackageManagerService
CVSS 5.3
CVE-2021-45335 HIGH
Avast Antivirus < 20.4 - Incorrect Default Permissions in Sandbox Component
CVSS 8.8
CVE-2021-21912 HIGH
Advantech R-SeeNet 2.4.15 - Privilege Escalation via File Replacement
CVSS 7.8
CVE-2021-21911 HIGH
Advantech R-SeeNet 2.4.15 - Privilege Escalation via File Replacement
CVSS 7.8
CVE-2021-21910 HIGH
Advantech R-SeeNet 2.4.15 - Privilege Escalation via File Replacement
CVSS 7.8
CVE-2021-44858 HIGH
MediaWiki < 1.35.5, 1.36.x < 1.36.3, 1.37.x < 1.37.1 - Unauthenticated Private Page Access via Undo and Restore Actions
CVSS 7.5
CVE-2021-0979 MEDIUM
Android 12 - Local Information Disclosure via ShortcutService Permissions Bypass
CVSS 5.5
CVE-2021-43326 HIGH
Automox Agent <32 - Privilege Escalation
CVSS 7.8
Details
Vulnerabilities 1,512
Exploit Likelihood Medium