CWE-275
61 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-275page 1 of 2
- CVE-2012-5628MEDIUMCVSS 4.42018-05-04
gofer before 0.68 uses world-writable permissions for /var/lib/gofer/journal/watchdog, which allows local users to cause a denial of service by removing journal entries.
- CVE-2013-3703HIGHCVSS 8.82018-06-08
The controller of the Open Build Service API prior to version 2.4.4 is missing a write permission check, allowing an authenticated attacker to add or remove user roles from packages and/or project meta data.
- CVE-2013-4040MEDIUMCVSS 5.52018-05-01
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2.x before 7.2.1.5 and 7.2.x before 7.2.2.0 on Unix use weak permissions (755) for unspecified configuration and log files, which allows local users to obtain sensitive inform…
- CVE-2013-4201MEDIUMCVSS 4.32018-05-01
Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.
- CVE-2014-1422MEDIUMCVSS 5.0EG 5.02020-07-22
In Ubuntu's trust-store, if a user revokes location access from an application, the location is still available to the application because the application will honour incorrect, cached permissions. This is because the cache was not ordered…
- CVE-2014-1631HIGHCVSS 7.5EG 7.52018-01-31
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
- CVE-2014-1632HIGHCVSS 8.1EG 8.12018-01-31
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the hostname parameter.
- CVE-2014-6047MEDIUMCVSS 5.3EG 5.32018-08-28
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
- CVE-2016-10796LOWCVSS 3.3EG 3.32019-08-06
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
- CVE-2016-10818MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
- CVE-2016-10846HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
- CVE-2016-5299HIGHCVSS 7.52018-06-11
A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems …
- CVE-2016-7066HIGHCVSS 7.82018-09-11
It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.
- CVE-2016-8520HIGHCVSS 8.82018-02-15
HPE Helion Eucalyptus v4.3.0 and earlier does not correctly check IAM user's permissions for accessing versioned objects and ACLs. In some cases, authenticated users with S3 permissions could also access versioned data.
- CVE-2016-8732HIGHCVSS 7.82018-04-24
Multiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on the driver communication channel and additional insufficient checks allow any application to turn of…
- CVE-2016-9061HIGHCVSS 7.52018-06-11
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and ope…
- CVE-2017-1396MEDIUMCVSS 4.22018-08-06
IBM Security Identity Governance Virtual Appliance 5.2 through 5.2.3.2 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 127342.
- CVE-2017-1418MEDIUMCVSS 4.02018-11-26
IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0.9) has insecure permissions on certain files. A local attacker could exploit this vulnerability to modify or delete th…
- CVE-2017-16887CRITICALCVSS 9.82018-01-12
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.
- CVE-2017-17060CRITICALCVSS 9.82019-05-23
OX Software GmbH OX App Suite 7.8.4 and earlier is affected by: Insecure Permissions.
- CVE-2017-18390HIGHCVSS 7.8EG 7.82019-08-02
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
- CVE-2017-18397LOWCVSS 3.3EG 3.32019-08-02
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
- CVE-2017-18422LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
- CVE-2017-18425LOWCVSS 2.5EG 2.52019-08-02
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
- CVE-2017-18427LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
- CVE-2017-2590HIGHCVSS 8.12018-07-27
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delet…
- CVE-2017-5809MEDIUMCVSS 5.52018-02-15
A Remote Arbitrary Code Execution vulnerability in HPE Data Protector version prior to 8.17 and 9.09 was found.
- CVE-2017-9327MEDIUMCVSS 6.5EG 6.52019-07-03
Secret data of processes managed by CM is not secured by file permissions.
- CVE-2018-0392MEDIUMCVSS 5.52018-07-18
A vulnerability in the CLI of Cisco Policy Suite could allow an authenticated, local attacker to access files owned by another user. The vulnerability is due to insufficient access control permissions (i.e., World-Readable). An attacker co…
- CVE-2018-0449MEDIUMCVSS 4.22019-01-10
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated priv…
- CVE-2018-15379CRITICALCVSS 9.82018-10-05
A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to exec…
- CVE-2019-11145HIGHCVSS 7.8EG 7.82019-08-19
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-11146HIGHCVSS 7.8EG 7.82019-08-19
Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2019-12622MEDIUMCVSS 5.5EG 5.52019-08-21
A vulnerability in Cisco RoomOS Software could allow an authenticated, local attacker to write files to the underlying filesystem with root privileges. The vulnerability is due to insufficient permission restrictions on a specific process.…
- CVE-2019-15962MEDIUMCVSS 4.4EG 4.42019-10-16
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device. The vulnerability is due to improper permission…
- CVE-2019-1618HIGHCVSS 7.82019-03-11
A vulnerability in the Tetration Analytics agent for Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker to execute arbitrary code as root. The vulnerability is due to an incorrect permiss…
- CVE-2019-2177HIGHCVSS 8.8EG 8.82019-09-05
In isPreferred of HidProfile.java in Android 7.1.1, 7.1.2, 8.0, 8.1 and 9, there is a possible device type confusion due to a permissions bypass. This could lead to remote code execution with no additional execution privileges needed. User…
- CVE-2020-14496HIGHCVSS 8.3EG 9.82022-05-19
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could c…
- CVE-2020-3152MEDIUMCVSS 6.7EG 6.72020-08-26
A vulnerability in Cisco Connected Mobile Experiences (CMX) could allow an authenticated, local attacker with administrative credentials to execute arbitrary commands with root privileges. The vulnerability is due to improper user permissi…
- CVE-2020-6022MEDIUMCVSS 5.5EG 5.52020-10-27
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
- CVE-2020-8471HIGHCVSS 7.8EG 7.82020-04-29
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+…
- CVE-2020-8474HIGHCVSS 7.8EG 7.82020-04-22
Weak Registry permissions in ABB System 800xA Base allow low privileged users to read and modify registry settings related to control system functionality, allowing an authenticated attacker to cause system functions to stop or malfunction.
- CVE-2021-1437HIGHCVSS 7.5EG 7.52021-03-24
A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to an u…
- CVE-2021-22566CRITICALCVSS 9.8EG 9.82022-01-18
An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as executable from an unprivileged context. This can be leveraged by an attacker to bypass executability restrictions of kern…
- CVE-2021-22571MEDIUMCVSS 5.5EG 5.52022-03-18
A local attacker could read files from some other users' SA360 reports stored in the /tmp folder during staging process before the files are loaded in BigQuery. We recommend upgrading to version 1.0.3 or above.
- CVE-2021-32006MEDIUMCVSS 5.0EG 4.32022-03-10
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Permission Issues vulnerability in LinkManager web portal of Secomea GateManager allows logged in LinkManager user to access stored SiteManager backup fi…
- CVE-2022-0343LOWCVSS 3.3EG 7.82022-03-29
A local attacker, as a different local user, may be able to send a HTTP request to 127.0.0.1:10000 after the user (typically a developer) manually invoked the ./tools/run-dev-server script. It is recommended to upgrade to any version beyon…
- CVE-2022-0742CRITICALCVSS 9.1EG 7.52022-03-18
Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539f…
- CVE-2022-22251HIGHCVSS 7.8EG 7.82022-10-18
On cSRX Series devices software permission issues in the container filesystem and stored files combined with storing passwords in a recoverable format in Juniper Networks Junos OS allows a local, low-privileged attacker to elevate their pe…
- CVE-2022-22988HIGHCVSS 7.7EG 9.12022-01-13
File and directory permissions have been corrected to prevent unintended users from modifying or accessing resources. It would be more difficult for an authenticated attacker to now traverse through the files and directories. This can only…
Map vulnerabilities like CWE-275 to your infrastructure
EchelonGraph correlates every CVE — across CWE-275 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →