Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-11-09 CVE-2021-43199 Incorrect Default Permissions vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
network
low complexity
jetbrains CWE-276
5.3
2021-11-03 CVE-2021-38420 Incorrect Default Permissions vulnerability in Deltaww Dialink 1.2.4.0
Delta Electronics DIALink versions 1.2.4.0 and prior default permissions give extensive permissions to low-privileged user accounts, which may allow an attacker to modify the installation directory and upload malicious files.
local
low complexity
deltaww CWE-276
7.8
2021-10-28 CVE-2021-3579 Incorrect Default Permissions vulnerability in Bitdefender Endpoint Security Tools and Total Security
Incorrect Default Permissions vulnerability in the bdservicehost.exe and Vulnerability.Scan.exe components as used in Bitdefender Endpoint Security Tools for Windows, Total Security allows a local attacker to elevate privileges to NT AUTHORITY\SYSTEM This issue affects: Bitdefender Endpoint Security Tools for Windows versions prior to 7.2.1.65.
local
low complexity
bitdefender CWE-276
7.8
2021-10-28 CVE-2021-22475 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is an Improper permission management vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei CWE-276
5.3
2021-10-28 CVE-2021-36989 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is a Kernel crash vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
network
low complexity
huawei CWE-276
critical
9.8
2021-10-28 CVE-2021-36990 Incorrect Default Permissions vulnerability in Huawei Emui and Magic UI
There is a vulnerability of tampering with the kernel in Huawei Smartphone.Successful exploitation of this vulnerability may escalate permissions.
network
low complexity
huawei CWE-276
critical
9.8
2021-10-27 CVE-2021-38379 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
local
low complexity
northern-tech CWE-276
5.5
2021-10-26 CVE-2021-37363 Incorrect Default Permissions vulnerability in Gestionaleopen Gestionale Open 11.00.00
An Insecure Permissions issue exists in Gestionale Open 11.00.00.
local
low complexity
gestionaleopen CWE-276
7.8
2021-10-21 CVE-2021-42011 Incorrect Default Permissions vulnerability in Trendmicro Apex ONE 2019
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations.
local
low complexity
trendmicro CWE-276
7.8
2021-10-21 CVE-2021-40123 Incorrect Default Permissions vulnerability in Cisco Identity Services Engine
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted.
network
low complexity
cisco CWE-276
6.5