CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,512 vulnerabilities with CWE-276
CVE-2020-12277
MEDIUM
GitLab 10.8-12.9 - Unauthenticated Repository Mirroring via Unauthorized Feature Access
CVSS 5.3
CVE-2020-8471
HIGH
ABB Central Licensing Server - Authenticated Arbitrary Code Execution via Weak File Permissions
CVSS 7.8
CVE-2020-12118
HIGH
Binance tss-lib < 1.2.0 - Keygen Protocol Parameter Manipulation
CVSS 8.2
CVE-2020-8798
MEDIUM
Juplink RX4-1500 Firmware 1.0.3-1.0.5 - Unauthenticated Router Settings Access via setup3.htm Endpoint
CVSS 5.5
CVE-2020-12075
HIGH
Data Tables Generator by Supsystic < 1.9.92 - Unauthenticated Incorrect Default Permissions
CVSS 8.8
CVE-2020-11692
LOW
JetBrains YouTrack < 2020.1.659 - Incorrect Default Permissions for DB Export
CVSS 2.7
CVE-2020-11689
MEDIUM
JetBrains TeamCity < 2019.2.1 - Unauthenticated Settings Import via settings.kts
CVSS 6.5
CVE-2020-0547
HIGH
Intel Data Migration Software <= 3.3 - Authenticated Privilege Escalation via Installer Default Permissions
CVSS 7.8
CVE-2020-4274
MEDIUM
IBM QRadar 7.3.0-7.3.3 Patch 2 - Authenticated Unauthorized Data Access via Inadequate Permission Checks
CVSS 5.4
CVE-2020-4270
HIGH
IBM QRadar 7.3.0-7.3.3 Patch 2 - Privilege Escalation via Weak File Permissions
CVSS 7.8
CVE-2020-7802
MEDIUM
SSS HUSKY RTU 6049-E70 <5.0 - Info Disclosure
CVSS 5.3
CVE-2020-6456
MEDIUM
Google Chrome < 81.0.4044.92 - Site Isolation Bypass via Clipboard Input
CVSS 6.5
CVE-2020-6446
MEDIUM
Google Chrome < 81.0.4044.92 - Content Security Policy Bypass via Trusted Types
CVSS 6.5
CVE-2020-6445
MEDIUM
Google Chrome < 81.0.4044.92 - Content Security Policy Bypass via Trusted Types
CVSS 6.5
CVE-2020-6441
MEDIUM
Google Chrome < 81.0.4044.92 - Incorrect Default Permissions
CVSS 4.3
CVE-2020-6439
HIGH
Google Chrome < 81.0.4044.92 - Security UI Bypass via Crafted HTML Page
CVSS 8.8
CVE-2020-6431
MEDIUM
Google Chrome < 81.0.4044.92 - Security UI Spoofing via Full Screen Policy Enforcement
CVSS 4.3
CVE-2020-1985
HIGH
Secdo - Incorrect Default Permissions in Logs Folder
CVSS 7.8
CVE-2020-7004
HIGH
VISAM VBASE Editor 11.5.0.2 and VBASE Web-Remote Module - Insecure Directory Permissions
CVSS 8.8
CVE-2020-11444
HIGH
Sonatype Nexus Repository Manager 3.0.0-3.21.2 - Incorrect Access Control
CVSS 8.8
CVE-2020-5551
HIGH
Toyota Display Control Unit - Unauthenticated Denial of Service and Arbitrary Command Execution via Bluetooth
CVSS 8.8
CVE-2020-10939
HIGH
PHOENIX CONTACT PC WORX SRT <1.14 - Privilege Escalation
CVSS 7.8
CVE-2020-3766
HIGH
Adobe Genuine Integrity Service <6.4 - Privilege Escalation
CVSS 7.8
CVE-2020-9392
HIGH
Pricing Table by Supsystic < 1.8.2 - Unauthenticated Arbitrary Table Creation and Data Exposure
CVSS 7.3
CVE-2020-10660
MEDIUM
HashiCorp Vault <1.3.3 - Info Disclosure
CVSS 5.3
Details
Vulnerabilities
1,512
Exploit Likelihood
Medium