Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-06-21 CVE-2021-34387 Incorrect Default Permissions vulnerability in Nvidia Jetson Linux
The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where the portion of the DRAM reserved for TrustZone is identity-mapped by TLK with read, write, and execute permissions, which gives write access to kernel code and data that is otherwise mapped read only.
local
low complexity
nvidia CWE-276
7.2
2021-06-17 CVE-2021-0143 Incorrect Default Permissions vulnerability in Intel Brand Verification Tool
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
4.6
2021-06-10 CVE-2021-21736 Incorrect Default Permissions vulnerability in ZTE Zxhn Hs562 Firmware 1.0.0.0B2.0000/1.0.0.0B3.0000
A smart camera product of ZTE is impacted by a permission and access control vulnerability.
network
low complexity
zte CWE-276
8.0
2021-06-10 CVE-2021-31998 Incorrect Default Permissions vulnerability in Opensuse INN 2.4.2170.21.3.1
A Incorrect Default Permissions vulnerability in the packaging of inn of SUSE Linux Enterprise Server 11-SP3; openSUSE Backports SLE-15-SP2, openSUSE Leap 15.2 allows local attackers to escalate their privileges from the news user to root.
local
low complexity
opensuse CWE-276
7.2
2021-06-09 CVE-2021-0058 Incorrect Default Permissions vulnerability in Intel Lapbc510 Firmware and Lapbc710 Firmware
Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
4.6
2021-06-09 CVE-2021-0100 Incorrect Default Permissions vulnerability in Intel SSD Data Center Tool 3.0.17/3.0.23
Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
4.6
2021-06-09 CVE-2021-0106 Incorrect Default Permissions vulnerability in Intel Ipmctl
Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
4.6
2021-06-09 CVE-2020-27384 Incorrect Default Permissions vulnerability in Arena Guild Wars 2 106916
The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice.
local
low complexity
arena CWE-276
4.6
2021-05-28 CVE-2021-27032 Incorrect Default Permissions vulnerability in Autodesk Licensing Services 9.0.1.1462.100
Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues.
local
low complexity
autodesk CWE-276
7.8
2021-05-27 CVE-2020-10145 Incorrect Default Permissions vulnerability in Adobe Coldfusion 2016/2018/2021
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\.
local
low complexity
adobe CWE-276
7.2