Vulnerabilities > Incorrect Default Permissions
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-23 | CVE-2022-28999 | Incorrect Default Permissions vulnerability in Bloodshed Dev-C++ 4.9.9.2 Insecure permissions in the install directories and binaries of Dev-CPP v4.9.9.2 allows attackers to execute arbitrary code via overwriting the binary devcpp.exe. | 8.8 |
2022-05-23 | CVE-2022-29376 | Incorrect Default Permissions vulnerability in Apachefriends Xampp Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | 8.8 |
2022-05-23 | CVE-2022-28932 | Incorrect Default Permissions vulnerability in Dlink Dsl-G2452Dg Firmware D-Link DSL-G2452DG HW:T1\\tFW:ME_2.00 was discovered to contain insecure permissions. | 9.8 |
2022-05-17 | CVE-2022-0486 | Incorrect Default Permissions vulnerability in Fidelissecurity Deception and Network Improper file permissions in the CommandPost, Collector, Sensor, and Sandbox components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected files and enable escalation of privileges equivalent to the root user. | 7.8 |
2022-05-17 | CVE-2022-0997 | Incorrect Default Permissions vulnerability in Fidelissecurity Deception and Network Improper file permissions in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with local, administrative access to the CLI to modify affected script files, which could result in arbitrary commands being run as root upon subsequent logon by a root user. | 7.8 |
2022-05-17 | CVE-2022-24890 | Incorrect Default Permissions vulnerability in Nextcloud Talk Nextcloud Talk is a video and audio conferencing app for Nextcloud. | 4.3 |
2022-05-13 | CVE-2022-30367 | Incorrect Default Permissions vulnerability in AIR Cargo Management System Project AIR Cargo Management System 1.0 Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img. | 6.5 |
2022-05-13 | CVE-2022-30375 | Incorrect Default Permissions vulnerability in Simple Social Networking Site Project Simple Social Networking Site 1.0 Sourcecodester Simple Social Networking Site v1.0 is vulnerable to file deletion via /sns/classes/Master.php?f=delete_img. | 6.5 |
2022-05-06 | CVE-2022-23802 | Incorrect Default Permissions vulnerability in Ijoomla Guru 5.2.5 Joomla Guru extension 5.2.5 is affected by: Insecure Permissions. | 7.5 |
2022-04-28 | CVE-2022-29585 | Incorrect Default Permissions vulnerability in Mahara In Mahara before 20.10.5, 21.04.4, 21.10.2, and 22.04.0, a site using Isolated Institutions is vulnerable if more than ten groups are used. | 7.5 |