CWE-276
Medium likelihoodIncorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
1,512 vulnerabilities with CWE-276
CVE-2015-7378
HIGH
Panda Security URL Filtering < 4.3.1.8 - Privilege Escalation via Weak Directory ACL
CVSS 7.8
CVE-2015-7985
Valve Steam <2.10.91.91 - Privilege Escalation
CVE-2014-7210
CRITICAL
pdns <3.3.1-1 - Privilege Escalation
CVSS 9.8
CVE-2014-2723
HIGH
FortiBalancer 400 1000 2000 3000 - Unauthenticated Privileged SSH Access via Configuration Error
CVSS 8.8
CVE-2014-2722
HIGH
FortiBalancer 400 1000 2000 3000 - Unauthenticated Privileged SSH Access via Configuration Error
CVSS 8.8
CVE-2014-2721
HIGH
FortiBalancer 400 1000 2000 3000 - Unauthenticated Privileged SSH Access via Configuration Error
CVSS 8.8
CVE-2014-7303
HIGH
SGI Tempo - Unprotected User Data Exposure via Weak File Permissions
CVSS 7.8
CVE-2014-7302
HIGH
SGI Tempo - Incorrect Default Permissions via vx Binary
CVSS 7.8
CVE-2014-7301
MEDIUM
SGI Tempo - Unprotected User Data Exposure via Weak File Permissions
CVSS 6.6
CVE-2013-4281
MEDIUM
Red Hat Openshift 1 - Unprotected Private Key Exposure via Weak /etc/openshift/server_priv.pem Permissions
CVSS 5.5
CVE-2013-4859
HIGH
INSTEON Hub 2242-222 - No Auth Required
CVSS 8.1
CVE-2013-4764
MEDIUM
Samsung Galaxy S3/S4 - Info Disclosure
CVSS 4.3
CVE-2013-4763
MEDIUM
Samsung Galaxy S3/S4 - Info Disclosure
CVSS 4.6
CVE-2013-1425
MEDIUM
ldap_git_backup < 1.0.4 - Unprotected Password Hash Exposure via Incorrect Directory Permissions
CVSS 5.5
CVE-2013-4394
systemd < 194 - Privilege Escalation via XKB Layout Configuration
CVE-2013-0266
MEDIUM
OpenStack Essex - Information Disclosure via World-Readable Configuration Files
CVSS 5.5
CVE-2013-0632
CRITICAL
KEV
Adobe ColdFusion 9.0-9.0.2, 10 - Unauthenticated Authentication Bypass and Remote Code Execution via RDS Component
CVSS 9.8
CVE-2012-4434
HIGH
fwknop < 2.0.3 - Authenticated Denial of Service or Remote Code Execution
CVSS 8.8
CVE-2012-5578
MEDIUM
Python keyring < 0.10 - Insecure Database File Permissions
CVSS 6.2
CVE-2012-6136
MEDIUM
tuned 2.10.0 - Incorrect Default Permissions in PID File
CVSS 5.5
CVE-2012-1157
MEDIUM
Moodle < 2.2.2 - Unauthenticated Repository Access via Default Permissions
CVSS 4.3
CVE-2012-5577
HIGH
Python keyring lib <0.10 - Info Disclosure
CVSS 7.5
CVE-2012-4453
dracut < 024 - Incorrect Default Permissions in initramfs Images
CVE-2011-1762
MEDIUM
WordPress < 3.0.6 - Improper Access Control in wp-admin/press-this.php
CVSS 6.5
CVE-2011-4361
MediaWiki <1.17.1 - Info Disclosure
Details
Vulnerabilities
1,512
Exploit Likelihood
Medium