CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2019-11765 MEDIUM
Firefox < 70.0 - Permission Bypass via Compromised Content Process
CVSS 6.5
CVE-2019-16716 MEDIUM
OX App Suite <7.10.2 - Info Disclosure
CVSS 6.6
CVE-2019-11097 HIGH
Intel Trusted Execution Engine Firmware < 3.1.70 - Incorrect Default Permissions
CVSS 7.8
CVE-2019-19724 HIGH
Singularity <3.5.1 - Info Disclosure
CVSS 7.5
CVE-2019-8731 MEDIUM
iPhone OS < 13.0 - Unprotected User Data Exposure via Incorrect File Permissions
CVSS 5.5
CVE-2019-17334 HIGH
TIBCO Spotfire Analyst < 7.11.1 - Remote Code Execution via DXP File Injection
CVSS 8.0
CVE-2019-19675 HIGH
Ivanti Workspace Control <10.3.180.0 - Privilege Escalation
CVSS 7.8
CVE-2019-16559 MEDIUM
Jenkins WebSphere Deployer Plugin <1.6.1 - Info Disclosure
CVSS 5.4
CVE-2019-16554 MEDIUM
Jenkins Build Failure Analyzer Plugin <1.24.1 - Info Disclosure
CVSS 4.3
CVE-2019-16552 MEDIUM
Jenkins Gerrit Trigger Plugin <2.30.1 - Privilege Escalation
CVSS 5.4
CVE-2019-19712 MEDIUM
Contao 4.0-4.8.5 - Unauthenticated Information Disclosure via Backend Details View URL
CVSS 5.3
CVE-2019-15011 MEDIUM
Atlassian Application Links <5.0.12, 5.1.0-5.2.11, 5.3.0-5.3.7, 5.4.0-5.4.13, 6.0.0-6.0.5 - Information Disclosure
CVSS 4.3
CVE-2019-14605 HIGH
Intel(R) SCS Platform Discovery Utility - Privilege Escalation
CVSS 7.8
CVE-2019-14603 HIGH
Intel Quartus Prime Pro <19.3 - Privilege Escalation
CVSS 7.8
CVE-2019-14568 HIGH
Intel(R) RST <17.7.0.1006 - Privilege Escalation
CVSS 7.8
CVE-2019-0134 HIGH
Intel Dynamic Platform and Thermal Framework < 8.3.10208.5643 - Privilege Escalation via Incorrect Default Permissions
CVSS 7.8
CVE-2019-14861 MEDIUM
Samba 4.0.0-4.9.16, 4.10.0-4.10.10, 4.11.0-4.11.2 - Authenticated Memory Corruption via DNS Record Enumeration
CVSS 5.3
CVE-2019-19460 MEDIUM
SALTO ProAccess SPACE 5.4.3.0 - Privilege Escalation
CVSS 5.5
CVE-2019-19118 MEDIUM
Django 2.1 <2.1.15 & 2.2 <2.2.8 - Privilege Escalation
CVSS 6.5
CVE-2019-19490 HIGH
LiteManager 4.5.0 - Info Disclosure
CVSS 7.3
CVE-2019-13662 MEDIUM
Google Chrome <77.0.3865.75 - Auth Bypass
CVSS 6.5
CVE-2019-19202 HIGH
Vtiger <7.2.0 - Privilege Escalation
CVSS 8.8
CVE-2019-17421 HIGH
Zoho ManageEngine OpManager and Firewall Analyzer 12.4.072 - Privilege Escalation via Nipper Executable Overwrite
CVSS 7.8
CVE-2019-14602 HIGH
Nuvoton* CIR Driver <1.02.1002 - Privilege Escalation
CVSS 7.8
CVE-2019-4652 HIGH
IBM Spectrum Protect Plus <10.1.5 - Info Disclosure
CVSS 7.1
Details
Vulnerabilities 1,512
Exploit Likelihood Medium