CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2021-25317 LOW
SUSE Linux Enterprise Server <11-SP4-LTSS - Privilege Escalation
CVSS 3.3
CVE-2021-25319 HIGH
openSUSE Factory VirtualBox <6.1.20-1.1 - Privilege Escalation
CVSS 7.8
CVE-2021-26804 MEDIUM
Centreon Web 19.10.18 20.04.8 20.10.2 - Unauthenticated File Upload via Image Extension Spoofing
CVSS 6.5
CVE-2021-3451 MEDIUM
Lenovo PCManager < 3.0.400.3252 - Denial of Service via Configuration File Misplacement
CVSS 5.5
CVE-2021-28271 HIGH
Soyal Technologies SOYAL 701Server 9.0.1 - Privilege Escalation
CVSS 8.8
CVE-2021-20532 HIGH
IBM Spectrum Protect Client <8.1.11.0 - Privilege Escalation
CVSS 7.8
CVE-2021-0246 HIGH
Juniper Networks Junos OS - Privilege Escalation
CVSS 7.3
CVE-2021-0235 HIGH
Juniper Networks Junos OS - Privilege Escalation
CVSS 7.3
CVE-2021-30494 MEDIUM
Razer Synapse 3 - Unauthenticated Arbitrary File Write via Chroma SDK Log File Path Manipulation
CVSS 5.5
CVE-2021-30493 MEDIUM
Razer Synapse 3 - Privilege Escalation
CVSS 5.5
CVE-2021-3462 MEDIUM
Lenovo Power Management Driver < 1.67.17.54 - Privilege Escalation via Unauthorized Device Object Access
CVSS 5.5
CVE-2021-25381 MEDIUM
Samsung Account 10.8.0.4 and 12.1.1.3 - Unauthorized Action via PendingIntent Hijacking
CVSS 5.5
CVE-2021-25359 MEDIUM
SELinux <SMR APR-2021 Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-25358 MEDIUM
SMR APR-2021 < Release 1 - Info Disclosure
CVSS 4.0
CVE-2021-22538 MEDIUM
Google Exposure Notifications Verification Server < 0.23.1 - Improper Input Validation
CVSS 6.3
CVE-2021-27193 CRITICAL
Netop Vision Pro <= 9.7.1 - Unauthenticated Privilege Escalation via API Incorrect Default Permissions
CVSS 9.8
CVE-2021-25355 MEDIUM
Samsung Notes <4.2.00.22 - Privilege Escalation
CVSS 5.5
CVE-2021-22311 HIGH
Huawei ManageOne 8.0.0, 8.0.1 - Incorrect Default Permissions
CVSS 7.2
CVE-2021-21438 LOW
OTRS FAQ < 6.0.29 and OTRS < 7.0.24 - Unauthorized FAQ Article Access via Permission Bypass
CVSS 3.5
CVE-2021-0381 MEDIUM
Android 11 - Local Information Disclosure via Unsafe PendingIntent in DeviceStorageMonitorService
CVSS 5.5
CVE-2021-24032 MEDIUM
Zstandard 1.4.1-1.4.8 - Insecure Inherited Permissions via Output File Creation
CVSS 4.7
CVE-2021-24031 MEDIUM
Zstandard < 1.4.1 - Insecure Inherited Permissions
CVSS 5.5
CVE-2021-20653 MEDIUM
NEC CSDJ Firmware - Unauthenticated Historical Data Exposure via Access Restriction Bypass
CVSS 5.3
CVE-2021-3394 HIGH
Millewin 13.39.028 13.39.28.3342 13.39.146.1 - Local Privilege Escalation via Insecure Folder Permissions
CVSS 8.8
CVE-2021-21436 LOW
OTRS CIS in Customer Frontend < 7.0.14 - Unauthorized Config Item Access
CVSS 3.5
Details
Vulnerabilities 1,512
Exploit Likelihood Medium