Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2021-03-10 CVE-2021-0381 Incorrect Default Permissions vulnerability in Google Android 11.0
In updateNotifications of DeviceStorageMonitorService.java, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-276
5.5
2021-03-09 CVE-2020-8357 Incorrect Default Permissions vulnerability in Lenovo Pcmanager 2.6.40.3154/2.8.90.11211/3.0.50.9162
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.
local
low complexity
lenovo CWE-276
5.5
2021-03-04 CVE-2021-24032 Incorrect Default Permissions vulnerability in Facebook Zstandard
Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility created output files with default permissions and restricted those permissions immediately afterwards.
local
high complexity
facebook CWE-276
4.7
2021-03-04 CVE-2021-24031 Incorrect Default Permissions vulnerability in Facebook Zstandard
In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions.
local
low complexity
facebook CWE-276
5.5
2021-03-03 CVE-2020-13554 Incorrect Default Permissions vulnerability in Advantech Webaccess/Scada 9.0.1
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation.
local
low complexity
advantech CWE-276
7.8
2021-02-22 CVE-2020-22475 Incorrect Default Permissions vulnerability in Tasks
"Tasks" application version before 9.7.3 is affected by insecure permissions.
low complexity
tasks CWE-276
6.8
2021-02-19 CVE-2020-13549 Incorrect Default Permissions vulnerability in Sytech Xlreporter 14.0.1
An exploitable local privilege elevation vulnerability exists in the file system permissions of Sytech XL Reporter v14.0.1 install directory.
local
low complexity
sytech CWE-276
7.8
2021-02-18 CVE-2020-36233 Incorrect Default Permissions vulnerability in Atlassian Bitbucket
The Microsoft Windows Installer for Atlassian Bitbucket Server and Data Center before version 6.10.9, 7.x before 7.6.4, and from version 7.7.0 before 7.10.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
local
low complexity
atlassian CWE-276
7.8
2021-02-17 CVE-2020-13555 Incorrect Default Permissions vulnerability in Advantech Webaccess/Scada 9.0.1
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation.
local
low complexity
advantech CWE-276
8.8
2021-02-17 CVE-2020-13553 Incorrect Default Permissions vulnerability in Advantech Webaccess/Scada 9.0.1
An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation.
local
low complexity
advantech CWE-276
8.8