CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2019-1982 MEDIUM
Cisco Firepower HTTP Filter Bypass via Malicious Headers
CVSS 5.3
CVE-2019-12752 MEDIUM
Symantec SONAR < 12.0.2 - Tamper Protection Bypass via Incorrect Default Permissions
CVSS 6.1
CVE-2019-18369 MEDIUM
JetBrains YouTrack < 2019.2.55152 - Incorrect Default Permissions
CVSS 5.3
CVE-2019-18367 MEDIUM
JetBrains TeamCity < 2019.1.2 - Incorrect Default Permissions
CVSS 5.3
CVE-2019-18366 MEDIUM
JetBrains TeamCity < 2019.1.2 - Secure Value Exposure via Build Runtime Parameters
CVSS 5.3
CVE-2019-14925 MEDIUM
Mitsubishielectric Smartrtu Firmware - Incorrect Default Permissions
CVSS 6.5
CVE-2019-10474 MEDIUM
Jenkins Global Post Script Plugin < 1.1.4 - Unauthenticated Information Disclosure via Script Listing
CVSS 4.3
CVE-2019-10473 MEDIUM
Jenkins Libvirt Slaves Plugin < 1.8.5 - Unauthenticated Credential ID Enumeration via Form Methods
CVSS 4.3
CVE-2019-10472 MEDIUM
Jenkins Libvirt Slaves Plugin < 1.8.5 - Missing Permission Check for SSH Credential Capture
CVSS 6.5
CVE-2019-10470 MEDIUM
Jenkins Kubernetes CI < 1.3 - Unauthenticated Credential ID Enumeration via Form Methods
CVSS 6.5
CVE-2019-10469 MEDIUM
Jenkins Kubernetes CI < 1.3 - Missing Permission Check for Credential Capture
CVSS 6.5
CVE-2019-10465 MEDIUM
Jenkins Deploy WebLogic Plugin < 4.1 - Server-Side Request Forgery and Information Disclosure via URL Connection
CVSS 4.3
CVE-2019-10463 MEDIUM
Jenkins Dynatrace Application Monitoring < 2.1.4 - Incorrect Default Permissions
CVSS 6.5
CVE-2019-16919 HIGH
Harbor 1.8.0-1.8.2 - Broken Access Control via Robot Account Creation
CVSS 7.5
CVE-2019-15962 MEDIUM
Cisco TelePresence CE - Privilege Escalation
CVSS 4.4
CVE-2019-14737 HIGH
Ubisoft Uplay 92.0.0.6280 - Insecure Default Permissions
CVSS 7.8
CVE-2019-17044 HIGH
BMC Patrol Agent 9.0.10i - Local Privilege Escalation via SUID Binary Shared Library Injection
CVSS 7.8
CVE-2019-17043 HIGH
BMC Patrol Agent 9.0.10i - Privilege Escalation via Weak SUID Binary Permissions
CVSS 7.8
CVE-2019-2173 HIGH
Android 7.1.1-9 - Local Privilege Escalation via ActivityStarter Permission Check
CVSS 7.8
CVE-2019-2114 HIGH
Android 8.0-9 - Local Privilege Escalation via NFC Default Permissions
CVSS 7.8
CVE-2019-14510 MEDIUM
Kaseya VSA RMM <9.5.0.22 - Privilege Escalation
CVSS 6.7
CVE-2019-17365 HIGH
Nix < 2.3 - Unauthorized User Profile Access via World-Writable Parent Directory
CVSS 7.8
CVE-2019-17383 CRITICAL
netaddr < 1.5.3 and 2.0.0-2.0.3 - Incorrect Default Permissions
CVSS 9.8
CVE-2019-17124 CRITICAL
Kramer VIAware 2.5.0719.1034 - Incorrect Access Control
CVSS 9.8
CVE-2019-16913 HIGH
PC Protect Antivirus 4.14.31 - Privilege Escalation via Weak Directory Permissions
CVSS 7.8
Details
Vulnerabilities 1,512
Exploit Likelihood Medium