Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-03-17 CVE-2022-25364 Incorrect Default Permissions vulnerability in Gradle Enterprise
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access.
network
high complexity
gradle CWE-276
8.1
2022-03-16 CVE-2021-39694 Incorrect Default Permissions vulnerability in Google Android 12.0
In parse of RoleParser.java, there is a possible way for default apps to get permissions explicitly denied by the user due to a permissions bypass.
local
low complexity
google CWE-276
7.8
2022-03-10 CVE-2021-44215 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
local
low complexity
northern-tech CWE-276
5.5
2022-03-10 CVE-2021-44216 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
local
low complexity
northern-tech CWE-276
5.5
2022-03-10 CVE-2021-3981 Incorrect Default Permissions vulnerability in multiple products
A flaw in grub2 was found where its configuration file, known as grub.cfg, is being created with the wrong permission set allowing non privileged users to read its content.
local
low complexity
gnu fedoraproject CWE-276
3.3
2022-03-10 CVE-2021-40049 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a permission control vulnerability in the PMS module.
network
low complexity
huawei CWE-276
7.5
2022-03-10 CVE-2021-40053 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a permission control vulnerability in the Nearby module.Successful exploitation of this vulnerability will affect availability and integrity.
network
low complexity
huawei CWE-276
critical
9.1
2022-03-10 CVE-2021-40059 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is a permission control vulnerability in the Wi-Fi module.
low complexity
huawei CWE-276
6.5
2022-03-10 CVE-2021-32006 Incorrect Default Permissions vulnerability in Secomea Gatemanager 9.6.621421014
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions.
network
low complexity
secomea CWE-276
4.3
2022-03-10 CVE-2021-20269 Incorrect Default Permissions vulnerability in Kexec-Tools Project Kexec-Tools
A flaw was found in the permissions of a log file created by kexec-tools.
local
low complexity
kexec-tools-project CWE-276
5.5