CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,682 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 4 of 34
- CVE-2019-15962MEDIUMCVSS 4.4EG 4.42019-10-16
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission…
- CVE-2019-16061HIGHCVSS 8.8EG 8.82020-03-19
A number of files on the NETSAS Enigma NMS server 65.0.0 and prior are granted weak world-readable and world-writable permissions, allowing any low privileged user with access to the system to read sensitive data (e.g., .htpasswd) and crea…
- CVE-2019-16106HIGHCVSS 7.5EG 7.52019-09-10
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to change the password of any user via the recruitment_online/personalData/act_acounttab.cfm txtNewUserName and hdNP fields.
- CVE-2019-16183LOWCVSS 2.7EG 2.72019-09-09
In Limesurvey before 3.17.14, admin users can run an integrity check without proper permissions.
- CVE-2019-16185HIGHCVSS 7.2EG 7.22019-09-09
In Limesurvey before 3.17.14, admin users can view, update, or delete reserved menu entries without proper permissions.
- CVE-2019-16186HIGHCVSS 7.2EG 7.22019-09-09
In Limesurvey before 3.17.14, admin users can access the plugin manager without proper permissions.
- CVE-2019-16355MEDIUMCVSS 5.5EG 5.52019-09-16
The File Session Manager in Beego 1.10.0 allows local users to read session files because of weak permissions for individual files.
- CVE-2019-16552MEDIUMCVSS 5.4EG 5.42019-12-17
A missing permission check in Jenkins Gerrit Trigger Plugin 2.30.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP URL or SSH server using attacker-specified credentials, or determine the …
- CVE-2019-16554MEDIUMCVSS 4.3EG 4.32019-12-17
A missing permission check in Jenkins Build Failure Analyzer Plugin 1.24.1 and earlier allows attackers with Overall/Read permission to have Jenkins evaluate a computationally expensive regular expression.
- CVE-2019-16559MEDIUMCVSS 5.4EG 5.42019-12-17
A missing permission check in Jenkins WebSphere Deployer Plugin 1.6.1 and earlier allows attackers with Overall/Read permission to perform connection tests and determine whether files with an attacker-specified path exist on the Jenkins ma…
- CVE-2019-16716MEDIUMCVSS 6.6EG 6.62020-01-06
OX App Suite through 7.10.2 has Incorrect Access Control.
- CVE-2019-16913HIGHCVSS 7.8EG 7.82019-10-07
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders. In addition, the p…
- CVE-2019-16919HIGHCVSS 7.5EG 7.52019-10-18
Harbor API has a Broken Access Control vulnerability. The vulnerability allows project administrators to use the Harbor API to create a robot account with unauthorized push and/or pull access permissions to a project they don't have access…
- CVE-2019-17043HIGHCVSS 7.8EG 7.82019-10-14
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the best1collect.exe SUID binary could allow an attacker to elevate his/her privileges to the ones of the "patrol" user by specially crafting a shared libra…
- CVE-2019-17044HIGHCVSS 7.8EG 7.82019-10-14
An issue was discovered in BMC Patrol Agent 9.0.10i. Weak execution permissions on the PatrolAgent SUID binary could allow an attacker with "patrol" privileges to elevate his/her privileges to the ones of the "root" user by specially craft…
- CVE-2019-17052LOWCVSS 3.3EG 3.32019-10-01
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
- CVE-2019-17053LOWCVSS 3.3EG 3.32019-10-01
ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154 network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
- CVE-2019-17054LOWCVSS 3.3EG 3.32019-10-01
atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
- CVE-2019-17056LOWCVSS 3.3EG 3.32019-10-01
llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-3a359798b176.
- CVE-2019-17103MEDIUMCVSS 4.9EG 5.52020-01-27
An Incorrect Default Permissions vulnerability in the BDLDaemon component of Bitdefender AV for Mac allows an attacker to elevate permissions to read protected directories. This issue affects: Bitdefender AV for Mac versions prior to 8.0.0.
- CVE-2019-17124CRITICALCVSS 9.8EG 9.82019-10-09
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
- CVE-2019-17334HIGHCVSS 8.0EG 8.02019-12-17
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains …
- CVE-2019-17365HIGHCVSS 7.8EG 7.82019-10-09
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
- CVE-2019-17383CRITICALCVSS 9.8EG 9.82019-10-09
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
- CVE-2019-17421HIGHCVSS 7.8EG 7.82019-11-21
Incorrect file permissions on the packaged Nipper executable file in Zoho ManageEngine OpManager 12.4.072 and Firewall Analyzer 12.4.072 allow local users to elevate privileges to root by overwriting this file with a malicious payload.
- CVE-2019-18366MEDIUMCVSS 5.3EG 5.32019-10-31
In JetBrains TeamCity before 2019.1.2, secure values could be exposed to users with the "View build runtime parameters and data" permission.
- CVE-2019-18367MEDIUMCVSS 5.3EG 5.32019-10-31
In JetBrains TeamCity before 2019.1.2, a non-destructive operation could be performed by a user without the corresponding permissions.
- CVE-2019-18369MEDIUMCVSS 5.3EG 5.32019-10-31
In JetBrains YouTrack before 2019.2.55152, removing tags from the issues list without the corresponding permission was possible.
- CVE-2019-18895HIGHCVSS 7.8EG 7.82019-11-14
Scanguard through 2019-11-12 on Windows has Insecure Permissions for the installation directory, leading to privilege escalation via a Trojan horse executable file.
- CVE-2019-18900MEDIUMCVSS 4.0EG 4.02020-01-24
: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allowed local attackers to read a cookie store used by libzypp, exposing private cookies. …
- CVE-2019-19118MEDIUMCVSS 6.5EG 6.52019-12-02
Django 2.1 before 2.1.15 and 2.2 before 2.2.8 allows unintended model editing. A Django model admin displaying inline related models, where the user has view-only permissions to a parent model but edit permissions to the inline model, woul…
- CVE-2019-19202HIGHCVSS 8.8EG 8.82019-11-21
In Vtiger 7.x before 7.2.0, the My Preferences saving functionality allows a user without administrative privileges to change his own role by adding roleid=H2 to a POST request.
- CVE-2019-19392CRITICALCVSS 9.8EG 9.82020-01-21
The forDNN.UsersExportImport module before 1.2.0 for DNN (formerly DotNetNuke) allows an unprivileged user to import (create) new users with Administrator privileges, as demonstrated by Roles="Administrators" in XML or CSV data.
- CVE-2019-19460MEDIUMCVSS 5.5EG 5.52019-12-03
An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. The product's webserver runs as a Windows service with local SYSTEM permissions by default. This is against the principle of least privilege. An attacker who is able to exploit CVE-…
- CVE-2019-19475HIGHCVSS 8.8EG 8.82020-01-10
An issue was discovered in ManageEngine Applications Manager 14 with Build 14360. Integrated PostgreSQL which is built-in in Applications Manager is prone to attack due to lack of file permission security. The malicious users who are in ��…
- CVE-2019-19490HIGHCVSS 7.3EG 7.32019-12-02
LiteManager 4.5.0 has weak permissions (Everyone: Full Control) in the "LiteManagerFree - Server" folder, as demonstrated by ROMFUSClient.exe.
- CVE-2019-19675HIGHCVSS 7.8EG 7.82019-12-17
In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, t…
- CVE-2019-19712MEDIUMCVSS 5.3EG 5.32019-12-17
Contao 4.0 through 4.8.5 has Insecure Permissions. Back end users can manipulate the details view URL to show pages and articles that have not been enabled for them.
- CVE-2019-19724HIGHCVSS 7.5EG 7.52019-12-18
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud…
- CVE-2019-19792MEDIUMCVSS 6.7EG 6.72020-03-03
A permissions issue in ESET Cyber Security before 6.8.300.0 for macOS allows a local attacker to escalate privileges by appending data to root-owned files.
- CVE-2019-1982MEDIUMCVSS 5.3EG 5.32019-11-05
A vulnerability in the HTTP traffic filtering component of Cisco Firepower Threat Defense Software, Cisco FirePOWER Services Software for ASA, and Cisco Firepower Management Center Software could allow an unauthenticated, remote attacker t…
- CVE-2019-19896CRITICALCVSS 9.9EG 9.92020-01-23
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), w…
- CVE-2019-20106MEDIUMCVSS 4.3EG 4.32020-02-06
Comment properties in Atlassian Jira Server and Data Center before version 7.13.12, from 8.0.0 before version 8.5.4, and 8.6.0 before version 8.6.1 allows remote attackers to make comments on a ticket to which they do not have commenting p…
- CVE-2019-20457CRITICALCVSS 9.1EG 9.12024-11-07
An issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authentication, because the response header of any failed login attempt returns an incomplete authorizati…
- CVE-2019-20458HIGHCVSS 8.8EG 8.82024-11-07
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices …
- CVE-2019-20468CRITICALCVSS 9.8EG 9.82021-02-01
An issue was discovered in SeTracker2 for TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It has unnecessary permissions such as READ_EXTERNAL_STORAGE, WRITE_EXTERNAL_STORAGE, and READ_CONTACTS.
- CVE-2019-20536CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2…
- CVE-2019-20882MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 5.8.0. It does not honor the domain requirement when processing a join request for an open team.
- CVE-2019-20889MEDIUMCVSS 5.3EG 5.32020-06-19
An issue was discovered in Mattermost Server before 5.7, 5.6.3, 5.5.2, and 4.10.5. It mishandles permissions for user-access token creation.
- CVE-2019-2114HIGHCVSS 7.8EG 7.82019-10-11
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission. This could lead to local escalation of privilege by installing an application with no …
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →