Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-08-24 CVE-2021-31000 Incorrect Default Permissions vulnerability in Apple products
A permissions issue was addressed with improved validation.
local
low complexity
apple CWE-276
3.3
2021-08-24 CVE-2021-31006 Incorrect Default Permissions vulnerability in Apple Watchos
Description: A permissions issue was addressed with improved validation.
local
low complexity
apple CWE-276
5.5
2021-08-24 CVE-2021-31007 Incorrect Default Permissions vulnerability in Apple products
Description: A permissions issue was addressed with improved validation.
local
low complexity
apple CWE-276
5.5
2021-08-19 CVE-2021-39273 Incorrect Default Permissions vulnerability in Xerosecurity Sn1Per 9.0
In XeroSecurity Sn1per 9.0 (free version), insecure permissions (0777) are set upon application execution, allowing an unprivileged user to modify the application, modules, and configuration files.
network
low complexity
xerosecurity CWE-276
critical
9.0
2021-08-19 CVE-2021-39274 Incorrect Default Permissions vulnerability in Xerosecurity Sn1Per 9.0
In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing an unprivileged user to modify the main application and the application configuration file.
network
low complexity
xerosecurity CWE-276
critical
10.0
2021-08-13 CVE-2021-37351 Incorrect Default Permissions vulnerability in Nagios XI
Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded pages through a crafted HTTP request to the server.
network
low complexity
nagios CWE-276
5.0
2021-08-06 CVE-2021-35312 Incorrect Default Permissions vulnerability in Gestionaleamica Amica Prodigy 1.7
A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7.
local
low complexity
gestionaleamica CWE-276
7.2
2021-08-06 CVE-2021-36795 Incorrect Default Permissions vulnerability in Cohesity Linux Agent 6.5.1D/6.6.0B
A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6.0a to 6.6.0b-hotfix1.
4.4
2021-08-06 CVE-2021-22295 Incorrect Default Permissions vulnerability in Huawei Harmonyos 2.0
A component of the HarmonyOS has a permission bypass vulnerability.
local
low complexity
huawei CWE-276
2.1
2021-08-04 CVE-2021-32464 Incorrect Default Permissions vulnerability in Trendmicro Apex ONE and Officescan
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed.
local
low complexity
trendmicro CWE-276
7.2