CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,512 vulnerabilities with CWE-276
CVE-2020-6497
MEDIUM
Google Chrome on iOS < 83.0.4103.88 - Domain Spoofing via Crafted URI
CVSS 6.5
CVE-2020-6495
MEDIUM
Google Chrome < 83.0.4103.97 - Sandbox Escape via Malicious Extension
CVSS 6.5
CVE-2020-2197
MEDIUM
Jenkins Project Inheritance Plugin < 19.08.02 - Unauthenticated Job Configuration Exposure via XML Format
CVSS 4.3
CVE-2020-2191
MEDIUM
Jenkins Self-Organizing Swarm Modules Plugin < 3.20 - Unauthenticated Agent Label Manipulation via API Endpoints
CVSS 4.3
CVE-2020-6488
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Downloads
CVSS 4.3
CVE-2020-6487
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Downloads
CVSS 6.5
CVE-2020-6484
MEDIUM
Google Chrome < 83.0.4103.61 - Navigation Restriction Bypass via ChromeDriver Request
CVSS 6.5
CVE-2020-6483
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Payments
CVSS 6.5
CVE-2020-6482
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Developer Tools
CVSS 6.5
CVE-2020-6480
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Enterprise Navigation Restrictions
CVSS 6.5
CVE-2020-6476
MEDIUM
Google Chrome < 83.0.4103.61 - Insufficient Policy Enforcement in Tab Strip
CVSS 6.5
CVE-2020-6471
CRITICAL
Google Chrome < 83.0.4103.61 - Sandbox Escape via Malicious Extension
CVSS 9.6
CVE-2020-6469
CRITICAL
Google Chrome < 83.0.4103.61 - Sandbox Escape via Malicious Extension
CVSS 9.6
CVE-2020-13240
MEDIUM
Dolibarr 11.0.4 - Stored Cross-Site Scripting via File Extension Bypass
CVSS 5.4
CVE-2020-11716
CRITICAL
Panasonic Eluga and P110 Firmware < 2020-04-10 - Insecure Default Permissions
CVSS 9.8
CVE-2020-9409
CRITICAL
TIBCO JasperReports Server < 7.1.1 - Unauthenticated Privilege Escalation to Superuser
CVSS 9.8
CVE-2020-13149
HIGH
Dragon Center <2.6.2003.2401 - Privilege Escalation
CVSS 7.8
CVE-2020-12834
CRITICAL
eQ-3 Homematic CCU2 < 2.51.6 & CCU3 < 3.51.6 - RCE via ReGa.runScript JSON API
CVSS 9.8
CVE-2020-0024
HIGH
Android 8.0-10 - Unauthorized Setting Modification via SettingsBaseActivity Permissions Bypass
CVSS 7.8
CVE-2020-4259
MEDIUM
IBM Sterling File Gateway 2.2.0.0-2.2.6.5_1 - Authenticated Privilege Escalation via Cookie Manipulation
CVSS 6.5
CVE-2020-5896
HIGH
BIG-IP Edge Client <7.1.10 - Info Disclosure
CVSS 7.8
CVE-2020-12608
HIGH
SolarWinds MSP PME <1.1.15 - Code Execution
CVSS 7.8
CVE-2020-2183
MEDIUM
Jenkins Copy Artifact Plugin < 1.43.1 - Unauthenticated Artifact Access via Improper Permission Checks
CVSS 6.5
CVE-2020-8018
HIGH
SUSE Linux Enterprise Server <15 SP1 - Privilege Escalation
CVSS 8.4
CVE-2020-12101
MEDIUM
xt:Commerce 5.1-6.2.2 - Authenticated Address Deletion via ID Manipulation
CVSS 4.3
Details
Vulnerabilities
1,512
Exploit Likelihood
Medium