Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-07-08 CVE-2020-5974 Incorrect Default Permissions vulnerability in Nvidia Jetpack Software Development KIT 4.2/4.3
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are incorrectly set on certain directories, which can lead to escalation of privileges.
local
low complexity
nvidia CWE-276
7.8
2020-07-07 CVE-2020-15578 Incorrect Default Permissions vulnerability in Google Android 8.0/8.1
An issue was discovered on Samsung mobile devices with O(8.x) software.
local
low complexity
google CWE-276
5.5
2020-07-01 CVE-2020-5906 Incorrect Default Permissions vulnerability in F5 products
In versions 13.1.0-13.1.3.3, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, the BIG-IP system does not properly enforce the access controls for the scp.blacklist files.
network
low complexity
f5 CWE-276
8.1
2020-06-29 CVE-2020-8022 Incorrect Default Permissions vulnerability in multiple products
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 12-SP2, SUSE Linux Enterprise Server for SAP 12-SP3, SUSE Linux Enterprise Server for SAP 15, SUSE OpenStack Cloud 7, SUSE OpenStack Cloud 8, SUSE OpenStack Cloud Crowbar 8 allows local attackers to escalate from group tomcat to root.
local
low complexity
apache opensuse CWE-276
7.8
2020-06-29 CVE-2020-8024 Incorrect Default Permissions vulnerability in Opensuse Hylafax+ 5.6.1Lp151.3.7/7.0.22.1
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries.
local
low complexity
opensuse CWE-276
5.3
2020-06-26 CVE-2020-15351 Incorrect Default Permissions vulnerability in Idrive
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions granting any user modify permission (i.e., NT AUTHORITY\Authenticated Users:(OI)(CI)(M)) to the contents of the directory and its sub-folders.
local
low complexity
idrive CWE-276
7.8
2020-06-22 CVE-2020-8933 Incorrect Default Permissions vulnerability in multiple products
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root.
local
low complexity
google opensuse CWE-276
7.8
2020-06-22 CVE-2020-8907 Incorrect Default Permissions vulnerability in multiple products
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root.
local
low complexity
google opensuse CWE-276
7.8
2020-06-22 CVE-2020-8903 Incorrect Default Permissions vulnerability in multiple products
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root.
local
low complexity
google opensuse CWE-276
7.8
2020-06-22 CVE-2020-3626 Incorrect Default Permissions vulnerability in Qualcomm products
Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ8096AU, APQ8098, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
local
low complexity
qualcomm CWE-276
7.8