CWE-276— Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.— MITRE CWE catalog
1,700 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-276page 1 of 34
- CVE-1999-0426CRITICALCVSS 9.8EG 9.81999-03-01
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
- CVE-2001-0497HIGHCVSS 7.8EG 7.82001-07-21
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and pe…
- CVE-2002-1713MEDIUMCVSS 5.5EG 5.52002-12-31
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.
- CVE-2002-1844HIGHCVSS 7.8EG 7.82002-12-31
Microsoft Windows Media Player (WMP) 6.3, when installed on Solaris, installs executables with world-writable permissions, which allows local users to delete or modify the executables to gain privileges.
- CVE-2004-1778MEDIUMCVSS v2 4.6EG 4.62004-12-22
Skype 0.92.0.12 and 1.0.0.1 for Linux, and possibly other versions, creates the /usr/share/skype/lang directory with world-writable permissions, which allows local users to modify language files and possibly conduct social engineering or o…
- CVE-2005-1941HIGHCVSS 7.8EG 7.82005-06-08
SilverCity before 0.9.5-r1 installs (1) cgi-styler-form.py, (2) cgi-styler.py, and (3) source2html.py with read and write world permissions, which allows local users to execute arbitrary code.
- CVE-2006-5014HIGHCVSS 8.8EG 8.82006-09-27
Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
- CVE-2010-4176MEDIUMCVSS v2 4.0EG 4.02010-12-07
plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.
- CVE-2010-5108HIGHCVSS 7.5EG 7.52019-11-13
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
- CVE-2011-1435MEDIUMCVSS v2 5.0EG 5.02011-05-03
Google Chrome before 11.0.696.57 does not properly implement the tabs permission for extensions, which allows remote attackers to read local files via a crafted extension.
- CVE-2011-1762MEDIUMCVSS 6.5EG 6.52022-04-18
A flaw exists in Wordpress related to the 'wp-admin/press-this.php 'script improperly checking user permissions when publishing posts. This may allow a user with 'Contributor-level' privileges to post as if they had 'publish_posts' permiss…
- CVE-2011-2782MEDIUMCVSS v2 4.3EG 4.32011-08-03
The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.
- CVE-2011-2859MEDIUMCVSS v2 6.8EG 6.82011-09-19
Google Chrome before 14.0.835.163 uses incorrect permissions for non-gallery pages, which has unspecified impact and attack vectors.
- CVE-2011-4361MEDIUMCVSS v2 5.0EG 5.02012-01-08
MediaWiki before 1.17.1 does not check for read permission before handling action=ajax requests, which allows remote attackers to obtain sensitive information by (1) leveraging the SpecialUpload::ajaxGetExistsWarning function, or by (2) le…
- CVE-2012-1157MEDIUMCVSS 4.3EG 4.32019-11-14
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
- CVE-2012-4434HIGHCVSS 8.8EG 8.82020-01-09
fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.
- CVE-2012-4453LOWCVSS v2 2.1EG 2.12012-10-09
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
- CVE-2012-5577HIGHCVSS 7.5EG 7.52019-10-28
Python keyring lib before 0.10 created keyring files with world-readable permissions.
- CVE-2012-5578MEDIUMCVSS 6.2EG 6.22019-11-25
Python keyring has insecure permissions on new databases allowing world-readable files to be created
- CVE-2012-6136MEDIUMCVSS 5.5EG 5.52019-11-20
tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes.
- CVE-2013-0266MEDIUMCVSS 5.5EG 5.52013-03-08
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A loc…
- CVE-2013-0632CRITICALCVSS 9.8EG 9.8⚠ KEV2013-01-17
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this se…
- CVE-2013-1425MEDIUMCVSS 5.5EG 5.52019-11-07
ldap-git-backup before 1.0.4 exposes password hashes due to incorrect directory permissions.
- CVE-2013-4281MEDIUMCVSS 5.5EG 5.52022-10-19
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
- CVE-2013-4394MEDIUMCVSS v2 5.9EG 5.92013-10-28
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server conf…
- CVE-2013-4763MEDIUMCVSS 4.6EG 4.62019-12-27
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
- CVE-2013-4764MEDIUMCVSS 4.3EG 4.32019-12-27
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
- CVE-2013-4859HIGHCVSS 8.1EG 8.12019-12-27
INSTEON Hub 2242-222 lacks Web and API authentication
- CVE-2014-2721HIGHCVSS 8.8EG 8.82020-03-19
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configura…
- CVE-2014-2722HIGHCVSS 8.8EG 8.82020-03-19
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configura…
- CVE-2014-2723HIGHCVSS 8.8EG 8.82020-03-19
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configura…
- CVE-2014-7210CRITICALCVSS 9.8EG 9.82025-06-26
pdns specific as packaged in Debian in version before 3.3.1-1 creates a too privileged MySQL user. It was discovered that the maintainer scripts of pdns-backend-mysql grant too wide database permissions for the pdns user. Other backends ar…
- CVE-2014-7301MEDIUMCVSS 6.6EG 6.62020-01-27
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading /etc/odapw.
- CVE-2014-7302HIGHCVSS 7.8EG 7.82020-01-27
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to change the permissions of arbitrary files by executing /opt/sgi/sgimc/bin/vx.
- CVE-2014-7303HIGHCVSS 7.8EG 7.82020-01-27
SGI Tempo, as used on SGI ICE-X systems, uses weak permissions for certain files, which allows local users to obtain password hashes and possibly other unspecified sensitive information by reading etc/dbdump.db.
- CVE-2015-7378HIGHCVSS 7.8EG 7.82016-04-18
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
- CVE-2015-9474HIGHCVSS 8.8EG 8.82019-10-10
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
- CVE-2015-9475HIGHCVSS 8.8EG 8.82019-10-10
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
- CVE-2015-9476HIGHCVSS 8.8EG 8.82019-10-10
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
- CVE-2015-9477HIGHCVSS 8.8EG 8.82019-10-10
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
- CVE-2016-20029MEDIUMCVSS 6.2EG 6.22026-03-16
ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files by modifying file paths used to retrieve local resources. Attackers can manipulate path parameters to bypass access co…
- CVE-2016-3943HIGHCVSS 7.8EG 7.82016-04-18
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileg…
- CVE-2016-5425HIGHCVSS 7.8EG 7.82016-10-13
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak permissions for /usr/lib/tmpfiles.d/tomcat.conf, which allows local users to gain root privileges by le…
- CVE-2016-6914HIGHCVSS 7.8EG 7.82017-12-27
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.
- CVE-2017-0369MEDIUMCVSS 6.5EG 6.52018-04-13
Mediawiki before 1.28.1 / 1.27.2 / 1.23.16 contains a flaw, allowing a sysops to undelete pages, although the page is protected against it.
- CVE-2017-0847CRITICALCVSS 9.8EG 9.82017-11-16
An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.
- CVE-2017-1000084MEDIUMCVSS 6.5EG 6.52017-10-05
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
- CVE-2017-1000089MEDIUMCVSS 5.3EG 5.32017-10-05
Builds in Jenkins are associated with an authentication that controls the permissions that the build has to interact with other elements in Jenkins. The Pipeline: Build Step Plugin did not check the build authentication it was running as a…
- CVE-2017-11156HIGHCVSS 7.8EG 7.82017-08-14
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecif…
- CVE-2017-11610CRITICALCVSS 8.8EG 9.02017-08-23
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord name…
Map vulnerabilities like CWE-276 to your infrastructure
EchelonGraph correlates every CVE — across CWE-276 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →