CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2021-1056 HIGH
NVIDIA GPU Display Driver - Info Disclosure
CVSS 7.1
CVE-2020-37160 MEDIUM
SprintWork 2.3.1 - Privilege Escalation
CVSS 6.2
CVE-2020-37129 CRITICAL
Memu Play 7.1.3 - Privilege Escalation
CVSS 9.8
CVE-2020-11921 HIGH
Lush 2 through 2020-02-25 - Unauthenticated Bluetooth Connection Hijacking
CVSS 8.8
CVE-2020-36695 MEDIUM
Hitachi Device Manager <8.8.5-02 - Info Disclosure
CVSS 6.6
CVE-2020-21514 HIGH
fluentd-ui 1.2.2 - Incorrect Default Permissions
CVSS 8.8
CVE-2020-36652 MEDIUM
Hitachi Ops Center and Analytics Products - Incorrect Default Permissions
CVSS 6.6
CVE-2020-36611 MEDIUM
Hitachi Tuning Manager <8.8.5-00 - Info Disclosure
CVSS 6.6
CVE-2020-36605 MEDIUM
Hitachi Infrastructure Analytics Advisor <4.4.0-00, Hitachi Ops Cen...
CVSS 6.6
CVE-2020-5355 MEDIUM
Dell EMC Isilon OneFS <= 8.2.2 - Incorrect Default Permissions in SSHD
CVSS 4.3
CVE-2020-14521 HIGH
Mitsubishi Electric Factory Automation - Code Injection
CVSS 8.3
CVE-2020-8741 HIGH
Intel(R) Thunderbolt(TM) - Privilege Escalation
CVSS 7.8
CVE-2020-5353 HIGH
Dell EMC Isilon OneFS <= 8.2.2 and PowerScale OneFS 9.0.0 - Unauthenticated Privilege Escalation via NFS UID Spoofing
CVSS 8.8
CVE-2020-26180 MEDIUM
Dell EMC Isilon OneFS >=8.1.0 & PowerScale OneFS 9.0.0 - Unauthenticated Data Access via remotesupport
CVSS 6.3
CVE-2020-29503 MEDIUM
Dell EMC PowerStore <1.0.3.0.5 - Info Disclosure
CVSS 4.1
CVE-2020-25593 MEDIUM
Acronis True Image < 2021 - Local Privilege Escalation via Insecure Folder Permissions
CVSS 6.7
CVE-2020-27384 HIGH
Guild Wars 2 <106916 - Privilege Escalation
CVSS 7.8
CVE-2020-10145 HIGH
Adobe ColdFusion - Improper Access Control in Default Installation Directory
CVSS 7.8
CVE-2020-13599 LOW
Zephyr < 1.14.2 - Incorrect Default Permissions in Settings and LittleFS
CVSS 3.3
CVE-2020-9451 MEDIUM
Acronis True Image 2020 24.5.22510 - Denial of Service via Hardlink Attack on Log File
CVSS 5.5
CVE-2020-9450 HIGH
Acronis True Image 2020 24.5.22510 - Unauthenticated Arbitrary Executable Whitelisting via REST API
CVSS 7.8
CVE-2020-28906 HIGH
Nagios XI < 5.7.5 and Nagios Fusion < 4.1.8 - Privilege Escalation via Insecure File Permissions
CVSS 8.8
CVE-2020-13667 MEDIUM
Drupal Core 8.8.0-8.8.9, 8.9.0-8.9.5, 9.0.0-9.0.5 - Access Bypass in Workspaces Module
CVSS 5.3
CVE-2020-21342 HIGH
zzcms 201910 - Insecure Default Permissions via Password Reset
CVSS 7.5
CVE-2020-27569 HIGH
Aviatrix VPN Client <2.8.2 - Code Injection
CVSS 7.5
Details
Vulnerabilities 1,512
Exploit Likelihood Medium