CWE-275
116 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-275page 3 of 3
- CVE-2017-7144MEDIUMCVSS 4.3EG 4.32017-10-23
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to track Safari Private Browsing users by leveraging cookie m…
- CVE-2016-4873MEDIUMCVSS 4.3EG 4.32017-04-17
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.
- CVE-2017-0884MEDIUMCVSS 4.3EG 4.32017-04-05
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folder…
- CVE-2016-9462MEDIUMCVSS 4.3EG 4.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a…
- CVE-2016-9461MEDIUMCVSS 4.3EG 4.32017-03-28
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an a…
- CVE-2016-2406MEDIUMCVSS 4.3EG 4.32017-03-20
The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by leveraging incorrect control of permissio…
- CVE-2018-0449MEDIUMCVSS 4.2EG 4.22019-01-10
A vulnerability in the Cisco Jabber Client Framework (JCF) software, installed as part of the Cisco Jabber for Mac client, could allow an authenticated, local attacker to corrupt arbitrary files on an affected device that has elevated priv…
- CVE-2016-10796LOWCVSS 3.3EG 3.32019-08-06
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130).
- CVE-2017-18427LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
- CVE-2017-18422LOWCVSS 3.3EG 3.32019-08-02
In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
- CVE-2017-18397LOWCVSS 3.3EG 3.32019-08-02
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
- CVE-2017-2694LOWCVSS 3.3EG 3.32017-11-22
The AlarmService component in HwVmall with software earlier than 1.5.2.0 versions has no control over calling permissions, allowing any third party to call. An attacker can construct a malicious application to call it. Consequently, alert …
- CVE-2016-7553LOWCVSS 3.3EG 3.32017-02-27
The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading th…
- CVE-2016-0394LOWCVSS 3.3EG 3.32017-02-01
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.
- CVE-2016-2877LOWCVSS 3.3EG 3.32016-11-30
IBM QRadar SIEM 7.1 before MR2 Patch 13 and 7.2 before 7.2.7 uses weak permissions for unspecified directories under the web root, which allows local users to modify data by writing to a file.
- CVE-2017-18425LOWCVSS 2.5EG 2.52019-08-02
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
Map vulnerabilities like CWE-275 to your infrastructure
EchelonGraph correlates every CVE — across CWE-275 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →