In onResume of AppManagementFragment.java, there is a possible way to prevent users from forgetting a previously connect
In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under S
In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a log
In getFullScreenIntentDecision of NotificationInterruptStateProviderImpl.java, there is a possible activity launch while
In onNullBinding of CallRedirectionProcessor.java, there is a possible long lived connection due to improper input valid
In bindPlayer of MediaControlPanel.java, there is a possible launch arbitrary activity in SysUI due to Unsafe Intent. Th
The MC990 X and UV300 RMC component has and inadequate default configuration that could be exploited to obtain enhanced
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, ma
A vulnerability in the client update process of Cisco AnyConnect Secure Mobility Client Software for Windows and Cisco S
In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due t
In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in
Incorrect Default Permissions vulnerability in the openSUSE Tumbleweed hawk2 package allows users with access to the hac
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS Ventura 13.5. A use
When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in
When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can mod
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protec
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows us
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows au
A vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker wi
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticate
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the aff
There is a permission and access control vulnerability in some ZTE AndroidTV STBs. Due to improper permission settings,
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Agent
An Insecure Permissions vulnerability in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to
The facial recognition module has a vulnerability in file permission control. Successful exploitation of this vulnerabil
The Download Manager WordPress plugin before 6.3.0 leaks master key information without the need for a password, allowin
Sensitive information disclosure due to insecure registry permissions. The following products are affected: Acronis Agen
The Settings module has the file privilege escalation vulnerability.Successful exploitation of this vulnerability may af
SoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference fil
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber
Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is th
Insecure permissions in Smart Soft advancedexport before v4.4.7 allow unauthenticated attackers to arbitrarily download
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information
In ebankIT 6, the public endpoints /public/token/Email/generate and /public/token/SMS/generate allow generation of OTP m
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect d
Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may
Incorrect Default Permissions vulnerability in Hitachi Ops Center Analyzer on Windows (Hitachi Ops Center Analyzer RAID
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations.
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under
application-collabora is an integration of Collabora Online in XWiki. As part of the application use cases, depending on
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file t
Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using I
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer handler, where memory pe
An issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive i
NGINX Management Suite default file permissions are set such that an authenticated attacker may be able to modify sensit
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started