Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2024-04-19 CVE-2024-29962 Incorrect Default Permissions vulnerability in Broadcom Brocade Sannav
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable.
local
low complexity
broadcom CWE-276
5.5
2024-04-19 CVE-2024-29967 Incorrect Default Permissions vulnerability in Broadcom Brocade Sannav
In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files.
local
low complexity
broadcom CWE-276
6.0
2024-03-28 CVE-2024-0259 Incorrect Default Permissions vulnerability in Fortra Robot Schedule
Fortra's Robot Schedule Enterprise Agent for Windows prior to version 3.04 is susceptible to privilege escalation.
local
low complexity
fortra CWE-276
7.3
2024-03-18 CVE-2024-1605 Incorrect Default Permissions vulnerability in BMC Control-M 9.0.20/9.0.20.214/9.0.21
BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that grants Write and Read permissions to all users.
local
low complexity
bmc CWE-276
7.8
2024-03-08 CVE-2024-23201 Incorrect Default Permissions vulnerability in Apple products
A permissions issue was addressed with additional restrictions.
local
low complexity
apple CWE-276
5.5
2024-03-08 CVE-2024-23253 Incorrect Default Permissions vulnerability in Apple Macos
A permissions issue was addressed with additional restrictions.
local
low complexity
apple CWE-276
3.3
2024-03-08 CVE-2024-23295 Incorrect Default Permissions vulnerability in Apple Visionos 1.0.2
A permissions issue was addressed to help ensure Personas are always protected This issue is fixed in visionOS 1.1.
local
low complexity
apple CWE-276
5.5
2024-03-06 CVE-2024-22889 Incorrect Default Permissions vulnerability in Plone 6.0.9
Due to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crafted request.
network
low complexity
plone CWE-276
7.5
2024-03-05 CVE-2024-20830 Incorrect Default Permissions vulnerability in Samsung Android 11.0/12.0
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock settings.
local
low complexity
samsung CWE-276
5.3
2024-03-05 CVE-2024-20841 Incorrect Default Permissions vulnerability in Samsung Account
Improper Handling of Insufficient Privileges in Samsung Account prior to version 14.8.00.3 allows local attackers to access data.
local
low complexity
samsung CWE-276
5.5