Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2019-10-11 CVE-2019-2114 Incorrect Default Permissions vulnerability in Google Android 8.0/8.1/9.0
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission.
local
low complexity
google CWE-276
7.8
2019-10-11 CVE-2019-14510 Incorrect Default Permissions vulnerability in Kaseya VSA
An issue was discovered in Kaseya VSA RMM through 9.5.0.22.
local
low complexity
kaseya CWE-276
6.7
2019-10-10 CVE-2015-9477 Incorrect Default Permissions vulnerability in Vernissage Project Vernissage 1.2.8
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
network
low complexity
vernissage-project CWE-276
8.8
2019-10-10 CVE-2015-9476 Incorrect Default Permissions vulnerability in Teardrop Project Teardrop 1.8.1
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
network
low complexity
teardrop-project CWE-276
8.8
2019-10-10 CVE-2015-9475 Incorrect Default Permissions vulnerability in Pont Project Pont 1.5
The Pont theme 1.5 for WordPress has insufficient restrictions on option updates.
network
low complexity
pont-project CWE-276
8.8
2019-10-10 CVE-2015-9474 Incorrect Default Permissions vulnerability in Simpolio Project Simpolio 1.3.2
The Simpolio theme 1.3.2 for WordPress has insufficient restrictions on option updates.
network
low complexity
simpolio-project CWE-276
8.8
2019-10-09 CVE-2019-17365 Incorrect Default Permissions vulnerability in Nixos NIX
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
local
low complexity
nixos CWE-276
7.8
2019-10-09 CVE-2019-17383 Incorrect Default Permissions vulnerability in Netaddr Project Netaddr
The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
network
low complexity
netaddr-project CWE-276
critical
9.8
2019-10-09 CVE-2019-17124 Incorrect Default Permissions vulnerability in Kramerav Viaware 2.5.0719.1034
Kramer VIAware 2.5.0719.1034 has Incorrect Access Control.
network
low complexity
kramerav CWE-276
critical
9.8
2019-10-07 CVE-2019-16913 Incorrect Default Permissions vulnerability in Pcprotect Antivirus 4.14.31
PC Protect Antivirus v4.14.31 installs by default to %PROGRAMFILES(X86)%\PCProtect with very weak folder permissions, granting any user full permission "Everyone: (F)" to the contents of the directory and its subfolders.
local
low complexity
pcprotect CWE-276
7.8