CWE-276

Medium likelihood

Incorrect Default Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

During installation, installed file permissions are set to allow anyone to modify those files.

1,512 vulnerabilities with CWE-276
CVE-2018-9467 CRITICAL
Android - Incorrect Web Origin Determination in UriTest.java getHost()
CVSS 9.8
CVE-2018-9432 HIGH
Android - Local Privilege Escalation via Bluetooth Permission Bypass
CVSS 7.8
CVE-2018-9369 HIGH
Android - Local Privilege Escalation via Fastboot Kernel Command Line Injection
CVSS 7.3
CVE-2018-21061 MEDIUM
Samsung Android N(7.1) and O(8.x) - Unauthenticated Critical Function Execution via Fake Charger
CVSS 6.8
CVE-2018-20090 HIGH
Cloudera Data Science Workbench <1.4.2 - Privilege Escalation
CVSS 8.3
CVE-2018-17860 HIGH
Cloudera CDH 5.x-5.15.1 6.x-6.0.1 - Insecure Default Permissions
CVSS 7.2
CVE-2018-2025 MEDIUM
IBM Spectrum Protect 7.1.0.0-7.1.8.5 - Incorrect Default Permissions in CIT Subdirectory
CVSS 4.4
CVE-2018-19592 HIGH
Corsair Link 4.9.7.35 - Privilege Escalation
CVSS 7.8
CVE-2018-7822 MEDIUM
SoMachine Basic and Modicon M221 < 1.10.0.0 - Unauthorized Access via Incorrect Default Permissions
CVSS 5.5
CVE-2018-13287 MEDIUM
Synology Router Manager < 1.1.7-6941-1 - Authenticated Sensitive Information Exposure via synouser.conf
CVSS 6.5
CVE-2018-13286 MEDIUM
Synology DiskStation Manager < 6.2-23739-1 - Authenticated Sensitive Information Exposure via synouser.conf
CVSS 6.5
CVE-2018-11906 HIGH
Android - Incorrect Default Permissions for ADB and Debug-fs
CVSS 7.8
CVE-2018-9085 MEDIUM
Lenovo and IBM System x Servers - Unprotected Flash Memory Modification via Unset Write Protection Lock Bit
CVSS 4.9
CVE-2018-12441 HIGH
Corsair Utility Engine - Command Injection
CVSS 7.8
CVE-2018-10605 HIGH
Martem TELEM GW6/GWM <2.0.87-4018403-k4 - Privilege Escalation
CVSS 8.8
CVE-2018-14650 MEDIUM
sos-collector - Unprotected Sensitive Data Exposure via Default File Permissions
CVSS 5.9
CVE-2018-8848 HIGH
Philips e-Alert Unit <R2.1 - Privilege Escalation
CVSS 7.5
CVE-2018-12175 HIGH
Intel Distribution for Python <2018 - Privilege Escalation
CVSS 7.8
CVE-2018-12160 MEDIUM
Intel Data Center Migration Center Software <3.1 - Code Injection
CVSS 5.3
CVE-2018-11454 HIGH
SIMATIC STEP 7 and WinCC (TIA Portal) V10-V15 - Unauthenticated Incorrect Default Permissions
CVSS 8.6
CVE-2018-11453 HIGH
Siemens Simatic Step 7 (tia Portal) - Incorrect Permission Assignment
CVSS 7.8
CVE-2018-14335 MEDIUM
H2 <1.4.197 - Info Disclosure
CVSS 6.5
CVE-2018-10604 HIGH
SEL Compass <3.0.5.1 - Privilege Escalation
CVSS 8.8
CVE-2018-6683 HIGH
McAfee Data Loss Prevention Endpoint < 10.0.505 - Local Policy Bypass via Local Policy File Editing
CVSS 7.4
CVE-2018-7535 HIGH
TotalAV 4.1.7-4.6.19 - Unauthenticated Arbitrary File Write via Weak Directory Permissions
CVSS 7.8
Details
Vulnerabilities 1,512
Exploit Likelihood Medium