Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2019-11765 Incorrect Default Permissions vulnerability in Mozilla Firefox
A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown.
network
low complexity
mozilla CWE-276
6.5
2020-01-08 CVE-2020-0009 Incorrect Default Permissions vulnerability in multiple products
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass.
local
low complexity
google debian CWE-276
5.5
2020-01-06 CVE-2019-16716 Incorrect Default Permissions vulnerability in Open-Xchange Appsuite
OX App Suite through 7.10.2 has Incorrect Access Control.
network
high complexity
open-xchange CWE-276
6.6
2019-12-27 CVE-2013-4859 Incorrect Default Permissions vulnerability in Insteon HUB Firmware 2242222
INSTEON Hub 2242-222 lacks Web and API authentication
network
high complexity
insteon CWE-276
8.1
2019-12-27 CVE-2013-4764 Incorrect Default Permissions vulnerability in Samsung Galaxy S3 Firmware and Galaxy S4 Firmware
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
low complexity
samsung CWE-276
4.3
2019-12-27 CVE-2013-4763 Incorrect Default Permissions vulnerability in Samsung Galaxy S3 Firmware and Galaxy S4 Firmware
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
low complexity
samsung CWE-276
4.6
2019-12-18 CVE-2019-11097 Incorrect Default Permissions vulnerability in Intel Trusted Execution Engine Firmware
Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2019-12-18 CVE-2019-19724 Incorrect Default Permissions vulnerability in Sylabs Singularity
Insecure permissions (777) are set on $HOME/.singularity when it is newly created by Singularity (version from 3.3.0 to 3.5.1), which could lead to an information leak, and malicious redirection of operations performed against Sylabs cloud services.
network
low complexity
sylabs CWE-276
7.5
2019-12-18 CVE-2019-8731 Incorrect Default Permissions vulnerability in Apple Iphone OS
A permissions issue existed in which execute permission was incorrectly granted.
local
low complexity
apple CWE-276
5.5
2019-12-17 CVE-2019-17334 Incorrect Default Permissions vulnerability in Tibco products
The Visualizations component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Deployment Kit, TIBCO Spotfire Desktop, and TIBCO Spotfire Desktop Language Packs contains a vulnerability that theoretically allows an attacker with permission to write DXP files to the Spotfire library to remotely execute code of their choice on the user account of other users who access the affected system.
network
low complexity
tibco CWE-276
8.0