Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-276

MITRE ↗

CWE-276

115
CRITICAL
732
HIGH
580
MEDIUM
61
LOW
1,529 CVEs · Page 11/31
7.3
CVE-2024-32368

Insecure Permission vulnerability in Agasta Sanketlife 2.0 Pocket 12-Lead ECG Monitor FW Version 3.0 allows a local atta

7.3
CVE-2023-46870

extcap/nrf_sniffer_ble.py, extcap/nrf_sniffer_ble.sh, extcap/SnifferAPI/*.py in Nordic Semiconductor nRF Sniffer for Blu

7.3
CVE-2023-31349

Incorrect default permissions in the AMD μProf installation directory could allow an attacker to achieve privilege escal

7.3
CVE-2024-21937

Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc

7.3
CVE-2024-21938

Incorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM)

7.3
CVE-2024-21939

Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow

7.3
CVE-2024-21945

Incorrect default permissions in the AMD RyzenTM Master monitoring SDK installation directory could allow an attacker to

7.3
CVE-2024-21946

Incorrect default permissions in the AMD RyzenTM Master Utility installation directory could allow an attacker to achiev

7.3
CVE-2024-21957

Incorrect default permissions in the AMD Management Console installation directory could allow an attacker to achieve pr

7.3
CVE-2024-21958

Incorrect default permissions in the AMD Provisioning Console installation directory could allow an attacker to achieve

7.3
CVE-2018-9369

In bootloader there is fastboot command allowing user specified kernel command line arguments. This could lead to local

7.2
CVE-2024-21820

Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SG

7.1
CVE-2023-38291

An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple devi

7.1
CVE-2024-4030

On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writ

7.1
CVE-2024-40805

A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS S

7.1
CVE-2023-45896

ntfs3 in the Linux kernel through 6.8.0 allows a physically proximate attacker to read kernel memory by mounting a files

7.1
CVE-2024-9191

The Okta Device Access features, provided by the Okta Verify agent for Windows, provides access to the OktaDeviceAccessP

7.0
CVE-2024-22428

Dell iDRAC Service Module, versions 5.2.0.0 and prior, contain an Incorrect Default Permissions vulnerability. It may a

7.0
CVE-2024-27134

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be

6.8
CVE-2024-2859

By default, SANnav OVA is shipped with root user login enabled. While protected by a password, access to root could exp

6.8
CVE-2024-34011

Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec

6.8
CVE-2024-50657

An issue in Owncloud android apk v.4.3.1 allows a physically proximate attacker to escalate privileges via the PassCodeV

6.7
CVE-2023-29244

Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop

6.7
CVE-2023-28739

Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authe

6.7
CVE-2023-34315

Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user t

6.7
CVE-2023-40154

Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged us

6.7
CVE-2023-41231

Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticat

6.7
CVE-2023-49721

An insecure default to allow UEFI Shell in EDK2 was left enabled in LXD. This allows an OS-resident attacker to bypass S

6.7
CVE-2023-28389

Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authentica

6.7
CVE-2024-25958

Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A

6.7
CVE-2023-42433

Incorrect default permissions in some Endurance Gaming Mode software installers before version 1.3.937.0 may allow an au

6.7
CVE-2023-42668

Incorrect default permissions in some onboard video driver software before version 1.14 for Intel(R) Server Boards based

6.7
CVE-2024-27180

An attacker with admin access can install rogue applications. As for the affected products/models/versions, see the refe

6.7
CVE-2023-43747

Incorrect default permissions for some Intel(R) Connectivity Performance Suite software installers before version 2.0 ma

6.7
CVE-2024-22378

Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1

6.7
CVE-2024-23495

Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authen

6.7
CVE-2024-23974

Incorrect default permissions in some Intel(R) ISH software installers may allow an authenticated user to potentially en

6.7
CVE-2024-26025

Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user t

6.7
CVE-2023-42133

PAX Android based POS devices allow for escalation of privilege via improperly configured scripts. An attacker must hav

6.7
CVE-2024-35287

A vulnerability in the NuPoint Messenger (NPM) component of Mitel MiCollab through version 9.8 SP1 (9.8.1.5) could allow

6.7
CVE-2024-25647

Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may

6.7
CVE-2024-29083

Incorrect default permissions in some Intel(R) Distribution for Python software before version 2024.2 may allow an authe

6.7
CVE-2024-35201

Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user

6.7
CVE-2017-13311

In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions

6.6
CVE-2023-6457

Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server componen

6.6
CVE-2024-24828

pkg is tool design to bundle Node.js projects into an executables. Any native code packages built by `pkg` are written t

6.6
CVE-2024-1605

BMC Control-M branches 9.0.20 and 9.0.21 upon user login load all Dynamic Link Libraries (DLL) from a directory that g

6.6
CVE-2024-32978

Kaminari is a paginator for web app frameworks and object relational mappings. A security vulnerability involving insecu

6.5
CVE-2024-6325

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/e

6.5
CVE-2024-38222

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Frequently Asked Questions

What is CWE-276?

CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-276?

There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.

How can I protect against CWE-276 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.

Detect CWE-276 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.

Get Started