Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-10463 Incorrect Default Permissions vulnerability in Jenkins Dynatrace Application Monitoring
A missing permission check in Jenkins Dynatrace Application Monitoring Plugin allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
network
low complexity
jenkins CWE-276
6.5
2019-10-18 CVE-2019-16919 Incorrect Default Permissions vulnerability in multiple products
Harbor API has a Broken Access Control vulnerability.
network
low complexity
linuxfoundation vmware CWE-276
7.5
2019-10-16 CVE-2019-15962 Incorrect Default Permissions vulnerability in Cisco Telepresence Collaboration Endpoint
A vulnerability in the CLI of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, local attacker to write files to the /root directory of an affected device.
local
low complexity
cisco CWE-276
4.4
2019-10-14 CVE-2019-14737 Incorrect Default Permissions vulnerability in Ubisoft Uplay 92.0.0.6280
Ubisoft Uplay 92.0.0.6280 has Insecure Permissions.
local
low complexity
ubisoft CWE-276
7.8
2019-10-14 CVE-2019-17044 Incorrect Default Permissions vulnerability in BMC Patrol Agent 9.0.10I
An issue was discovered in BMC Patrol Agent 9.0.10i.
local
low complexity
bmc CWE-276
7.8
2019-10-14 CVE-2019-17043 Incorrect Default Permissions vulnerability in BMC Patrol Agent 9.0.10I
An issue was discovered in BMC Patrol Agent 9.0.10i.
local
low complexity
bmc CWE-276
7.8
2019-10-11 CVE-2019-2173 Incorrect Default Permissions vulnerability in Google Android
In startActivityMayWait of ActivityStarter.java, there is a possible incorrect Activity launch due to an incorrect permission check.
local
low complexity
google CWE-276
7.8
2019-10-11 CVE-2019-2114 Incorrect Default Permissions vulnerability in Google Android 8.0/8.1/9.0
In the default privileges of NFC, there is a possible local bypass of user interaction requirements on package installation due to a default permission.
local
low complexity
google CWE-276
7.8
2019-10-11 CVE-2019-14510 Incorrect Default Permissions vulnerability in Kaseya VSA
An issue was discovered in Kaseya VSA RMM through 9.5.0.22.
local
low complexity
kaseya CWE-276
6.7
2019-10-10 CVE-2015-9477 Incorrect Default Permissions vulnerability in Vernissage Project Vernissage 1.2.8
The Vernissage theme 1.2.8 for WordPress has insufficient restrictions on option updates.
network
low complexity
vernissage-project CWE-276
8.8