CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,512 vulnerabilities with CWE-276
CVE-2019-3688
MEDIUM
SUSE Linux Enterprise Server squid - Incorrect Default Permissions in /usr/sbin/pinger
CVSS 5.1
CVE-2019-17056
LOW
Linux Kernel < 5.3.2 - Unprivileged Raw Socket Creation via AF_NFC Module
CVSS 3.3
CVE-2019-17054
LOW
Linux Kernel < 5.3.2 - Unauthenticated Raw Socket Creation via AF_APPLETALK Module
CVSS 3.3
CVE-2019-17053
LOW
Linux Kernel < 5.3.2 - Unauthenticated Raw Socket Creation via AF_IEEE802154
CVSS 3.3
CVE-2019-17052
LOW
Linux Kernel 3.16-5.3.2 - Unauthenticated Raw Socket Creation via AF_AX25 Module
CVSS 3.3
CVE-2019-12670
MEDIUM
Cisco IOS XE - Authenticated Namespace Container Protection Bypass via Insufficient File Permissions
CVSS 6.7
CVE-2019-3689
MEDIUM
nfs-utils < 1.3.0-34.18.1 - Incorrect Default Permissions in /var/lib/nfs Directory
CVSS 5.1
CVE-2019-9679
HIGH
Dahua Debug - Privilege Escalation
CVSS 8.8
CVE-2019-16355
MEDIUM
Beego 1.10.0 - Unauthenticated Session File Read via Weak File Permissions
CVSS 5.5
CVE-2019-16106
HIGH
Humanica Humatrix <7 - Info Disclosure
CVSS 7.5
CVE-2019-16186
HIGH
Limesurvey <3.17.14 - Privilege Escalation
CVSS 7.2
CVE-2019-16185
HIGH
Limesurvey <3.17.14 - Info Disclosure
CVSS 7.2
CVE-2019-16183
LOW
Limesurvey <3.17.14 - Info Disclosure
CVSS 2.7
CVE-2019-15716
MEDIUM
wtfutil/wtf < 0.19.0 - Unprotected Credential Exposure via Insecure Config File Permissions
CVSS 5.5
CVE-2019-5687
HIGH
NVIDIA Windows GPU Display Driver - Incorrect Default Permissions in Kernel Mode Layer Handler
CVSS 7.1
CVE-2019-9630
HIGH
Sonatype Nexus Repository Manager <3.17.0 - Info Disclosure
CVSS 7.5
CVE-2019-7588
MEDIUM
exacqVision ESM <5.12.2 - Privilege Escalation
CVSS 6.7
CVE-2019-12795
HIGH
gvfs < 1.38.3, 1.40.x < 1.40.2, 1.41.x < 1.41.3 - Unauthenticated D-Bus Method Call Execution via Private Server Socket
CVSS 7.8
CVE-2019-12450
CRITICAL
GLib 2.15.0-2.61.1 - Unrestricted File Permissions During Copy Operation
CVSS 9.8
CVE-2019-3870
MEDIUM
Samba 4.9.0-4.9.6 - Incorrect Default Permissions in AD DC Installation Directory
CVSS 6.1
CVE-2019-0683
MEDIUM
Active Directory - Privilege Escalation
CVSS 5.9
CVE-2018-25359
HIGH
Splinterware System Scheduler Pro 5.12 Privilege Escalation
CVSS 8.4
CVE-2018-9401
HIGH
Android - Local Privilege Escalation via Incorrect Bounds Check
CVSS 7.8
CVE-2018-9434
HIGH
Android - Local Privilege Escalation via Parcel.cpp ASLR Bypass
CVSS 7.8
CVE-2018-9431
HIGH
Android - Local Privilege Escalation via OSUInfo Input Validation
CVSS 7.8
Details
Vulnerabilities
1,512
Exploit Likelihood
Medium