Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-01-03 CVE-2021-39967 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
There is a Vulnerability of obtaining broadcast information improperly due to improper broadcast permission settings in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-276
7.5
2021-12-27 CVE-2021-45335 Incorrect Default Permissions vulnerability in Avast Antivirus
Sandbox component in Avast Antivirus prior to 20.4 has an insecure permission which could be abused by local user to control the outcome of scans, and therefore evade detection or delete arbitrary system files.
local
low complexity
avast CWE-276
8.8
2021-12-22 CVE-2021-21910 Incorrect Default Permissions vulnerability in Advantech R-Seenet 2.4.15
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021).
local
low complexity
advantech CWE-276
7.8
2021-12-22 CVE-2021-21912 Incorrect Default Permissions vulnerability in Advantech R-Seenet 2.4.15
A privilege escalation vulnerability exists in the Windows version of installation for Advantech R-SeeNet Advantech R-SeeNet 2.4.15 (30.07.2021).
local
low complexity
advantech CWE-276
7.8
2021-12-20 CVE-2021-44858 Incorrect Default Permissions vulnerability in Mediawiki
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1.
network
low complexity
mediawiki CWE-276
7.5
2021-12-15 CVE-2021-0979 Incorrect Default Permissions vulnerability in Google Android 12.0
In isRequestPinItemSupported of ShortcutService.java, there is a possible cross-user leak of packages in which the default launcher supports requests to create pinned shortcuts due to a permissions bypass.
local
low complexity
google CWE-276
5.5
2021-12-15 CVE-2021-43325 Incorrect Default Permissions vulnerability in Automox 33
Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory.
local
low complexity
automox CWE-276
7.8
2021-12-15 CVE-2021-43326 Incorrect Default Permissions vulnerability in Automox 31
Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
local
low complexity
automox CWE-276
7.8
2021-12-12 CVE-2021-44833 Incorrect Default Permissions vulnerability in Amazon AWS Opensearch 1.0.0
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
network
low complexity
amazon CWE-276
critical
9.8
2021-12-01 CVE-2021-42711 Incorrect Default Permissions vulnerability in Barracuda Network Access Client
Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions.
local
low complexity
barracuda CWE-276
7.8