CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 10 of 34
- CVE-2020-6483MEDIUMCVSS 6.5EG 6.52020-05-21
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2020-6484MEDIUMCVSS 6.5EG 6.52020-05-21
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
- CVE-2020-6487MEDIUMCVSS 6.5EG 6.52020-05-21
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2020-6488MEDIUMCVSS 4.3EG 4.32020-05-21
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
- CVE-2020-6495MEDIUMCVSS 6.5EG 6.52020-06-03
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
- CVE-2020-6497MEDIUMCVSS 6.5EG 6.52020-06-03
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
- CVE-2020-6498MEDIUMCVSS 6.5EG 6.52020-06-03
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
- CVE-2020-6501MEDIUMCVSS 6.5EG 6.52020-06-03
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2020-6502MEDIUMCVSS 6.5EG 6.52020-06-03
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
- CVE-2020-6504MEDIUMCVSS 4.3EG 4.32020-06-03
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.
- CVE-2020-6527MEDIUMCVSS 4.3EG 4.32020-07-22
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
- CVE-2020-7004HIGHCVSS 8.8EG 8.82020-04-03
VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the …
- CVE-2020-7527HIGHCVSS 7.8EG 7.82020-08-31
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege and provide full access control to local system users to SoMove component and services when a SoMove installer script i…
- CVE-2020-7802MEDIUMCVSS 5.3EG 5.32020-04-14
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has an Incorrect Default Permissions (CWE-276) vulnerability. The affected product is vulnerable to insufficient default permissions, which cou…
- CVE-2020-7824MEDIUMCVSS 6.5EG 6.52020-08-25
A vulnerability in the web-based management interface of iPECS could allow an authenticated, remote attacker to get administrator permission. The vulnerability is due to insecure permission when handling session cookies. An attacker could …
- CVE-2020-7943HIGHCVSS 7.5EG 7.52020-03-11
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which …
- CVE-2020-7967MEDIUMCVSS 4.3EG 4.32020-02-05
GitLab EE 8.0 through 12.7.2 has Insecure Permissions (issue 1 of 2).
- CVE-2020-7972HIGHCVSS 7.5EG 7.52020-02-05
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
- CVE-2020-7977MEDIUMCVSS 5.3EG 5.32020-02-05
GitLab EE 8.8 and later through 12.7.2 has Insecure Permissions.
- CVE-2020-7979MEDIUMCVSS 5.3EG 5.32020-02-05
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- CVE-2020-8018HIGHCVSS 8.4EG 8.42020-05-04
A Incorrect Default Permissions vulnerability in the SLES15-SP1-CHOST-BYOS and SLES15-SP1-CAP-Deployment-BYOS images of SUSE Linux Enterprise Server 15 SP1 allows local attackers with the UID 1000 to escalate to root due to a /etc director…
- CVE-2020-8022HIGHCVSS 7.7EG 7.72020-06-29
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux E…
- CVE-2020-8024MEDIUMCVSS 5.3EG 5.32020-06-29
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects:…
- CVE-2020-8026HIGHCVSS 8.4EG 8.42020-08-07
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15.1 allows local attackers with control of the new user to escalate their privileges to root. This issue affec…
- CVE-2020-8114CRITICALCVSS 9.8EG 9.82020-02-05
GitLab EE 8.9 and later through 12.7.2 has Insecure Permission
- CVE-2020-8219HIGHCVSS 7.2EG 7.22020-07-30
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.
- CVE-2020-8346MEDIUMCVSS 5.5EG 5.52020-09-15
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
- CVE-2020-8357MEDIUMCVSS 5.5EG 5.52021-03-09
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.
- CVE-2020-8471HIGHCVSS 7.8EG 7.82020-04-29
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+…
- CVE-2020-8539HIGHCVSS 7.8EG 7.82020-12-01
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities.…
- CVE-2020-8701MEDIUMCVSS 6.7EG 6.72021-02-17
Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-8741HIGHCVSS 7.8EG 7.82021-11-17
Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-8743HIGHCVSS 7.8EG 7.82020-08-13
Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-8763HIGHCVSS 7.8EG 7.82020-08-13
Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-8765MEDIUMCVSS 6.7EG 6.72021-02-17
Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.
- CVE-2020-8798MEDIUMCVSS 5.5EG 5.52020-04-23
httpd in Juplink RX4-1500 v1.0.3-v1.0.5 allows remote attackers to change or access router settings by connecting to the unauthenticated setup3.htm endpoint from the local network.
- CVE-2020-8903HIGHCVSS 7.8EG 7.82020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, …
- CVE-2020-8907HIGHCVSS 7.8EG 7.82020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" grou…
- CVE-2020-8933HIGHCVSS 7.8EG 7.82020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an…
- CVE-2020-8954MEDIUMCVSS 5.4EG 5.42020-06-08
OpenSearch Web browser 1.0.4.9 allows Intent Scheme Hijacking.[a link that opens another app in the browser can be manipulated]
- CVE-2020-9039CRITICALCVSS 9.8EG 9.82020-02-22
Couchbase Server 4.0.0, 4.1.0, 4.1.1, 4.5.0, 4.5.1, 4.6.0 through 4.6.5, 5.0.0, 5.1.1, 5.5.0 and 5.5.1 have Insecure Permissions for the projector and indexer REST endpoints (they allow unauthenticated access).The /settings REST endpoint e…
- CVE-2020-9392HIGHCVSS 7.3EG 7.32020-03-23
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permission check on the ImportJSONTable, createFromTpl, and getJSONExportTable endpoints, unauthenticated users can retrieve p…
- CVE-2020-9408HIGHCVSS 8.8EG 8.82020-03-11
The Spotfire library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace and TIBCO Spotfire Server contains a vulnerability that theoretically allows an attacker with write permissions to the Spotfire L…
- CVE-2020-9409CRITICALCVSS 9.8EG 9.82020-05-20
The administrative UI component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server for AWS Marketplace, and TIBCO JasperReports Server for ActiveMatrix BPM contains a vulnerability that theoretically allows an …
- CVE-2020-9450HIGHCVSS 7.8EG 7.82021-05-25
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unprivileged users. This API is used to communicate from the GUI to anti_ransomware_service.ex…
- CVE-2020-9451MEDIUMCVSS 5.5EG 5.52021-05-25
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged u…
- CVE-2020-9543HIGHCVSS 8.3EG 8.32020-03-12
OpenStack Manila <7.4.1, >=8.0.0 <8.1.1, and >=9.0.0 <9.1.1 allows attackers to view, update, delete, or share resources that do not belong to them, because of a context-free lookup of a UUID. Attackers may also create resources, such as s…
- CVE-2020-9817HIGHCVSS 7.8EG 7.82020-06-09
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in macOS Catalina 10.15.5. A malicious application may be able to gain root privileges.
- CVE-2021-0058HIGHCVSS 7.8EG 7.82021-06-09
Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2021-0065HIGHCVSS 7.8EG 7.82021-11-17
Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →