Skip to main content

CWE archive

CWE-276 CVEs

Programmatic archive

1,530 CVEs tagged with CWE-276118 Critical, 735 High, 616 Medium, 61 Low, 0 Unrated.

CVE-2019-15716

Published Aug 28, 2019

WTF before 0.19.0 does not set the permissions of config.yml, which might make it easier for local attackers to read passwords or API keys if the permissions were misconfigured or…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5687

Published Aug 6, 2019

NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which an incorrect use of default pe…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9630

Published Jul 8, 2019

Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository files and images.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-12795

Published Jun 11, 2019

daemon/gvfsdaemon.c in gvfsd from GNOME gvfs before 1.38.3, 1.40.x before 1.40.2, and 1.41.x before 1.41.3 opened a private D-Bus server socket without configuring an authorizatio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12450

Published May 29, 2019

file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissio…

CVSS 9.8 · Critical

CVE-2018-13287

Published Apr 1, 2019

Incorrect default permissions vulnerability in synouser.conf in Synology Router Manager (SRM) before 1.1.7-6941-1 allows remote authenticated users to obtain sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-13286

Published Apr 1, 2019

Incorrect default permissions vulnerability in synouser.conf in Synology Diskstation Manager (DSM) before 6.2-23739-1 allows remote authenticated users to obtain sensitive informa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11906

Published Nov 27, 2018

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, there is a security concern with default privileged access to ADB and de…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12441

Published Oct 11, 2018

The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modifi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-8848

Published Sep 26, 2018

Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12175

Published Sep 12, 2018

Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12160

Published Sep 12, 2018

DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-14335

Published Jul 24, 2018

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10604

Published Jul 24, 2018

SEL Compass version 3.0.5.1 and prior allows all users full access to the SEL Compass directory, which may allow modification or overwriting of files within the Compass installati…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1,451-1,475 of 1,530 CVEsPage 59 of 62