Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-09-17 CVE-2020-0308 Incorrect Default Permissions vulnerability in Google Android 11.0
In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-276
2.1
2020-09-17 CVE-2020-0297 Incorrect Default Permissions vulnerability in Google Android 11.0
In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-276
2.1
2020-09-17 CVE-2020-0296 Incorrect Default Permissions vulnerability in Google Android 11.0
In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent.
local
low complexity
google CWE-276
2.1
2020-09-17 CVE-2020-0275 Incorrect Default Permissions vulnerability in Google Android 11.0
In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass.
local
low complexity
google CWE-276
7.2
2020-09-17 CVE-2020-0390 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In the app zygote SE Policy, there is a possible permissions bypass.
local
low complexity
google CWE-276
2.1
2020-09-17 CVE-2020-0388 Incorrect Default Permissions vulnerability in Google Android 10.0/11.0
In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to an empty mutable PendingIntent.
local
low complexity
google CWE-276
7.2
2020-09-15 CVE-2020-8346 Incorrect Default Permissions vulnerability in Lenovo System Interface Foundation 1.1.18.3/1.1.19.3
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
local
low complexity
lenovo CWE-276
2.1
2020-09-09 CVE-2020-10050 Incorrect Default Permissions vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2).
local
low complexity
siemens CWE-276
7.2
2020-09-09 CVE-2020-10049 Incorrect Default Permissions vulnerability in Siemens Simatic Rtls Locating Manager 2.10/2.9.3
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2).
4.4
2020-09-03 CVE-2019-10679 Incorrect Default Permissions vulnerability in Thomsonreuters Eikon 4.0.42144
Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.
local
low complexity
thomsonreuters CWE-276
7.2