Vulnerable juju hook tool abstract UNIX domain socket. When combined with an attack of JUJU_CONTEXT_ID, any user on the
VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.
Delinea Privilege Manager before 12.0.2 mishandles the security of the Windows agent.
Incorrect access control in QuickHeal Antivirus Pro 24.1.0.182 and earlier allows authenticated attackers with low-level
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate non-administrator permis
In ICMPv6 Neighbor Discovery (ND), the ID is always 0. When pf is configured to allow ND and block incoming Echo Reques
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The shadow file is world reada
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could allow a local user to obtain sensitive information fr
Certain software builds for the Itel Vision 3 Turbo Android device contain a vulnerable pre-installed app with a package
Denial of service vulnerability present shortly after product installation or upgrade, potentially allowed an attacker t
A security issue was discovered in Kubernetes clusters with Windows nodes where BUILTIN\Users may be able to read contai
Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Incorrect default permissions issue exists in Unifier and Unifier Cast. If this vulnerability is exploited, arbitrary co
Incorrect default permissions vulnerability in firewall functionality in Synology Router Manager (SRM) before 1.2.5-8227
Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared mem
Incorrect default permissions in software installer for Intel(R) MAS (GUI) may allow an authenticated user to potentiall
Sysmac Studio installs executables in a directory with poor permissions. This can allow a locally-authenticated attacker
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local att
Ubuntu's pipewire-pulse in snap grants microphone access even when the snap interface for audio-record is not set.
A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability
Dell PowerScale OneFS versions 8.2.x through 9.6.0.x contains an incorrect default permissions vulnerability. A local l
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gai
A permissions issue was addressed with additional restrictions. This issue is fixed in tvOS 17.1, watchOS 10.1, macOS So
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS M
A permissions issue was addressed to help ensure Personas are always protected. This issue is fixed in visionOS 1.1. An
Microsoft Defender Security Feature Bypass Vulnerability
Insecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with l
Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. T
In multiple locations, there is a possible information leak due to a missing permission check. This could lead to local
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A mali
An incorrect permission in the installation directory for the shared NI SystemLink Server KeyValueDatabase service may r
A permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Snap D
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14
A potential information disclosure vulnerability was reported in Lenovo's packaging of Dolby Vision Provisioning softwar
Dell Secure Connect Gateway (SCG) 5.24 contains an Incorrect Default Permissions vulnerability. A local attacker with lo
In validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a thir
A security vulnerability has been identified in HPE Data Management Framework (DMF) Suite (CXFS). Depending on configura
A security vulnerability has been identified in HPE Cray Data Virtualization Service (DVS). Depending on configuration,
PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local
Vulnerability in the PeopleSoft Enterprise HCM Shared Components product of Oracle PeopleSoft (component: Text Catalog).
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ignazio Scimone Albo Pretorio On line.This i
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3
Incorrect default permission in AppLock prior to SMR MAr-2024 Release 1 allows local attackers to configure AppLock sett
The Ruby One Time Password library (ROTP) is an open source library for generating and validating one time passwords. Af
Permission verification vulnerability in the lock screen module. Impact: Successful exploitation of this vulnerability w
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started