CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2020-27228 HIGH
OpenClinic GA <5.173.3 - Privilege Escalation
CVSS 7.8
CVE-2020-13534 HIGH
Dream Report 5 R20-2 - Privilege Escalation
CVSS 7.8
CVE-2020-13533 HIGH
Dream Report 5 R20-2 - Privilege Escalation
CVSS 7.8
CVE-2020-13532 HIGH
Dream Report <5 R20-2 - Privilege Escalation
CVSS 7.8
CVE-2020-4976 MEDIUM
IBM DB2 9.7-11.5 - Unauthenticated Arbitrary File Read and Write via Weak File Permissions
CVSS 4.4
CVE-2020-8357 MEDIUM
Lenovo PCManager <3.0.200.2042 - DoS
CVSS 5.5
CVE-2020-13554 HIGH
Advantech WebAccess/SCADA 9.0.1 - Local Privilege Escalation via Insecure File Permissions
CVSS 7.8
CVE-2020-22475 MEDIUM
Tasks <9.7.3 - Privilege Escalation
CVSS 6.8
CVE-2020-13549 HIGH
Sytech XLReporter 14.0.1 - Local Privilege Escalation via Insecure File Permissions
CVSS 7.8
CVE-2020-36233 HIGH
Atlassian Bitbucket <6.10.9, 7.x<7.6.4, 7.7.0-7.10.1 Local Privilege Escalation
CVSS 7.8
CVE-2020-13555 HIGH
Advantech WebAccess/SCADA 9.0.1 - Local Privilege Escalation via Insecure File Permissions
CVSS 8.8
CVE-2020-13553 HIGH
Advantech WebAccess/SCADA 9.0.1 - Local Privilege Escalation via File System Permissions
CVSS 8.8
CVE-2020-13552 HIGH
Advantech WebAccess/SCADA 9.0.1 - Local Privilege Escalation via Service Executable Replacement
CVSS 8.8
CVE-2020-13551 HIGH
Advantech WebAccess/SCADA 9.0.1 - Local Privilege Escalation via PostgreSQL Executable
CVSS 8.8
CVE-2020-8765 MEDIUM
Intel(R) RealSense(TM) DCM - Privilege Escalation
CVSS 6.7
CVE-2020-8701 MEDIUM
Intel(R) SSD Toolbox <2/9/2021 - Privilege Escalation
CVSS 6.7
CVE-2020-0524 MEDIUM
Intel Ethernet Controller I210 Firmware < 3.30 - Authenticated Denial of Service via Local Access
CVSS 5.5
CVE-2020-28392 HIGH
SIMARIS configuration < 4.0.1 - Incorrect Default Permissions
CVSS 7.8
CVE-2020-16144 MEDIUM
ownCloud files_antivirus < 0.15.2 - Virus File Deletion Failure via Public Link Upload
CVSS 5.7
CVE-2020-25245 HIGH
DIGSI 4 < 4.94 - Unauthenticated DLL Hijacking via Writeable System Path
CVSS 7.8
CVE-2020-29582 MEDIUM
JetBrains Kotlin <1.4.21 - Info Disclosure
CVSS 5.3
CVE-2020-25208 MEDIUM
JetBrains YouTrack < 2020.4.4701 - Unauthenticated User Enumeration via REST API
CVSS 5.3
CVE-2020-26941 MEDIUM
ESET <version> - Privilege Escalation
CVSS 5.5
CVE-2020-11997 MEDIUM
Apache Guacamole < 1.2.0 - Unauthorized Connection History Access
CVSS 4.3
CVE-2020-13922 MEDIUM
Apache DolphinScheduler < 1.3.2 - Unauthenticated Password Override via API Interface
CVSS 6.5
Details
Vulnerabilities 1,512
Exploit Likelihood Medium