CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,684 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 6 of 34
- CVE-2020-0308MEDIUMCVSS 5.5EG 5.52020-09-17
In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi…
- CVE-2020-0310MEDIUMCVSS 5.5EG 5.52020-09-18
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi…
- CVE-2020-0311MEDIUMCVSS 5.5EG 5.52020-09-18
In InputManagerService, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: A…
- CVE-2020-0312MEDIUMCVSS 5.5EG 5.52020-09-17
In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Android…
- CVE-2020-0315MEDIUMCVSS 5.5EG 5.52020-09-18
In Zen Mode, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi…
- CVE-2020-0316MEDIUMCVSS 5.5EG 5.52020-09-18
In Telephony, there is a missing permission check. This could lead to local information disclosure of radio data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Andr…
- CVE-2020-0317MEDIUMCVSS 5.5EG 5.52020-09-17
In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi…
- CVE-2020-0343MEDIUMCVSS 5.5EG 5.52020-09-17
In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl…
- CVE-2020-0374HIGHCVSS 7.8EG 7.82020-09-17
In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- CVE-2020-0388HIGHCVSS 7.8EG 7.82020-09-17
In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent. This could lead to local escalation of privilege with User execution privileges needed.…
- CVE-2020-0390MEDIUMCVSS 5.5EG 5.52020-09-17
In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: …
- CVE-2020-0410MEDIUMCVSS 5.5EG 5.52020-10-14
In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2020-0412LOWCVSS 3.3EG 3.32020-10-14
In setProcessMemoryTrimLevel of ActivityManagerService.java, there is a missing permission check. This could lead to local information disclosure of foreground processes with no additional execution privileges needed. User interaction is n…
- CVE-2020-0414MEDIUMCVSS 6.5EG 6.52020-10-14
In AudioFlinger::RecordThread::threadLoop of audioflinger/Threads.cpp, there is a possible non-silenced audio buffer due to a permissions bypass. This could lead to remote information disclosure with no additional execution privileges need…
- CVE-2020-0415MEDIUMCVSS 5.5EG 5.52020-10-14
In various locations in SystemUI, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure of contact data with User execution privileges needed. User interaction is not needed f…
- CVE-2020-0426MEDIUMCVSS 5.5EG 5.52020-09-17
In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: …
- CVE-2020-0437MEDIUMCVSS 5.5EG 5.52020-11-10
In CellBroadcastReceiver's intent handlers, there is a possible denial of service due to a missing permission check. This could lead to local denial of service of emergency alerts with no additional execution privileges needed. User intera…
- CVE-2020-0439HIGHCVSS 7.8EG 7.82020-11-10
In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed …
- CVE-2020-0440HIGHCVSS 7.8EG 7.82020-12-14
In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges …
- CVE-2020-0448MEDIUMCVSS 5.5EG 5.52020-11-10
In getPhoneAccountsForPackage of TelecomServiceImpl.java, there is a possible way to access a tracking identifier due to a missing permission check. This could lead to local information disclosure of the identifier, which could be used to …
- CVE-2020-0453MEDIUMCVSS 5.5EG 5.52020-11-10
In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed …
- CVE-2020-0459LOWCVSS 3.3EG 3.32020-12-14
In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configuration data due to a missing permission check. This could lead to local information disclosure of WiFi network names with…
- CVE-2020-0468MEDIUMCVSS 5.5EG 5.52020-12-14
In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissions due to a missing permission check. This could lead to local information disclosure with no additional execution pri…
- CVE-2020-0475HIGHCVSS 7.8EG 7.82020-12-15
In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges ne…
- CVE-2020-0485HIGHCVSS 7.8EG 7.82020-12-15
In areFunctionsSupported of UsbBackend.java, there is a possible access to tethering from a guest account due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2020-0486HIGHCVSS 7.8EG 7.82020-12-15
In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default value. This could lead to local escalation of privilege to change contact data with no additional execution privileges nee…
- CVE-2020-0508HIGHCVSS 7.8EG 7.82020-03-12
Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable escalation of…
- CVE-2020-0514HIGHCVSS 7.8EG 7.82020-03-12
Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0524MEDIUMCVSS 5.5EG 5.52021-02-17
Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an authenticated user to potentially enable denial of service via local access.
- CVE-2020-0547HIGHCVSS 7.8EG 7.82020-04-15
Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0559HIGHCVSS 7.8EG 7.82020-08-13
Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0560HIGHCVSS 7.8EG 7.82020-02-13
Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0562HIGHCVSS 7.8EG 7.82020-02-13
Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-0564HIGHCVSS 7.8EG 7.82020-02-13
Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2020-10049HIGHCVSS 7.3EG 7.32020-09-09
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The start-stop scripts for the services of the affected application could allow a local attacker to include arbitrary commands that are executed…
- CVE-2020-10050HIGHCVSS 7.8EG 7.82020-09-09
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service executables of the affected application could allow a local attacker to include arbitrary commands that are executed wi…
- CVE-2020-10145HIGHCVSS 7.8EG 7.82021-05-27
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a …
- CVE-2020-10279CRITICALCVSS 9.8EG 9.82020-06-24
MiR robot controllers (central computation unit) makes use of Ubuntu 16.04.2 an operating system, Thought for desktop uses, this operating system presents insecure defaults for robots. These insecurities include a way for users to escalate…
- CVE-2020-10606HIGHCVSS 7.8EG 7.82020-07-24
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if t…
- CVE-2020-10660MEDIUMCVSS 5.3EG 5.32020-03-23
HashiCorp Vault and Vault Enterprise versions 0.9.0 through 1.3.3 may, under certain circumstances, have an Entity's Group membership inadvertently include Groups the Entity no longer has permissions to. Fixed in 1.3.4.
- CVE-2020-10782MEDIUMCVSS 6.5EG 6.52020-06-18
An exposure of sensitive information flaw was found in Ansible version 3.7.0. Sensitive information, such tokens and other secrets could be readable and exposed from the rsyslog configuration file, which has set the wrong world-readable pe…
- CVE-2020-10792HIGHCVSS 7.5EG 7.52020-03-20
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
- CVE-2020-10939HIGHCVSS 7.8EG 7.82020-03-27
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
- CVE-2020-11444HIGHCVSS 8.8EG 8.82020-04-02
Sonatype Nexus Repository Manager 3.x up to and including 3.21.2 has Incorrect Access Control.
- CVE-2020-11689MEDIUMCVSS 6.5EG 6.52020-04-22
In JetBrains TeamCity before 2019.2.1, a user without appropriate permissions was able to import settings from the settings.kts file.
- CVE-2020-11692LOWCVSS 2.7EG 2.72020-04-22
In JetBrains YouTrack before 2020.1.659, DB export was accessible to read-only administrators.
- CVE-2020-11716CRITICALCVSS 9.8EG 9.82020-05-20
Panasonic P110, Eluga Z1 Pro, Eluga X1, and Eluga X1 Pro devices through 2020-04-10 have Insecure Permissions. NOTE: the vendor states that all affected products are at "End-of-software-support."
- CVE-2020-11867LOWCVSS 3.3EG 3.32020-11-30
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files loca…
- CVE-2020-11921HIGHCVSS 8.8EG 8.82024-11-07
An issue was discovered in Lush 2 through 2020-02-25. Due to the lack of Bluetooth traffic encryption, it is possible to hijack an ongoing Bluetooth connection between the Lush 2 and a mobile phone. This allows an attacker to gain full con…
- CVE-2020-11955HIGHCVSS 8.8EG 8.82020-07-14
An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →