Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-07-30 CVE-2020-8219 Incorrect Default Permissions vulnerability in multiple products
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.
network
low complexity
pulsesecure ivanti CWE-276
7.2
2020-07-29 CVE-2020-2077 Incorrect Default Permissions vulnerability in Sick Package Analytics 04.0.0
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions settings.
network
low complexity
sick CWE-276
7.5
2020-07-24 CVE-2020-10606 Incorrect Default Permissions vulnerability in Osisoft products
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software.
local
low complexity
osisoft CWE-276
7.8
2020-07-22 CVE-2020-6527 Incorrect Default Permissions vulnerability in multiple products
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
network
low complexity
google debian opensuse fedoraproject CWE-276
4.3
2020-07-20 CVE-2020-15852 Incorrect Default Permissions vulnerability in multiple products
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests.
local
low complexity
linux xen netapp CWE-276
7.8
2020-07-17 CVE-2020-0122 Incorrect Default Permissions vulnerability in Google Android
In the permission declaration for com.google.android.providers.gsf.permission.WRITE_GSERVICES in AndroidManifest.xml, there is a possible permissions bypass.
local
low complexity
google CWE-276
6.7
2020-07-15 CVE-2020-6165 Incorrect Default Permissions vulnerability in Silverstripe
SilverStripe 4.5.0 allows attackers to read certain records that should not have been placed into a result set.
network
low complexity
silverstripe CWE-276
5.3
2020-07-14 CVE-2020-11955 Incorrect Default Permissions vulnerability in Rittal products
An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices.
network
low complexity
rittal CWE-276
8.8
2020-07-09 CVE-2020-12415 Incorrect Default Permissions vulnerability in multiple products
When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory.
network
low complexity
mozilla opensuse CWE-276
6.5
2020-07-09 CVE-2020-12424 Incorrect Default Permissions vulnerability in multiple products
When constructing a permission prompt for WebRTC, a URI was supplied from the content process.
network
low complexity
mozilla opensuse CWE-276
6.5