Any application can bind to it and exercise the APIs due to no protection for AIDL uimlpaservice in Snapdragon Auto, Sna
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is on
IDrive before 6.7.3.19 on Windows installs by default to %PROGRAMFILES(X86)%\IDriveWindows with weak folder permissions
NVIDIA JetPack SDK, version 4.2 and 4.3, contains a vulnerability in its installation scripts in which permissions are i
An issue was discovered in the Linux kernel 5.5 through 5.7.9, as used in Xen through 4.13.x for x86 PV guests. An attac
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected
Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authentica
Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticate
Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an
OpenZFS before 2.0.0-rc1, when used on FreeBSD, misinterprets group permissions as user permissions, as demonstrated by
Incorrect Default Permission vulnerability exists in SoMove (V2.8.1) and prior which could cause elevation of privilege
Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFIL
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.10.2). The directory of service
In createEmergencyLocationUserNotification of GnssVisibilityControl.java, there is a possible permissions bypass due to
In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access
In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of pri
Insecure permissions in Nakivo Backup & Replication Director version 9.4.0.r43656 on Linux allow local users to access t
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8
Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, ma
Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticat
Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenti
Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive
Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an au
Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentiall
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta
A local privilege elevation vulnerability exists in the file system permissions of LogicalDoc 8.5.1 installation. Depend
inSync Client installer for macOS versions v6.8.0 and prior could allow an attacker to gain privileges of a root user fr
In openAssetFileListener of ContactsProvider2.java, there is a possible permission bypass due to an insecure default val
A privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker ca
Digi XBee 2 devices do not have an effective protection mechanism against remote AT commands, because of issues related
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterp
GitLab EE 12.2 has Insecure Permissions (issue 2 of 2).
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For Pup
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placin
Parrot ANAFI is vulnerable to Wi-Fi deauthentication attack, allowing remote and unauthenticated attackers to disconnect
An issue was discovered on Samsung mobile devices with M(6.0) software. Attackers can prevent users from making outbound
An issue was discovered on Samsung mobile devices with N(7.x) software. Persona has an unprotected API that allows launc
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the sa
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription r
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0,
SICK Package Analytics software up to and including version V04.0.0 are vulnerable due to incorrect default permissions
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used).
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used).
gmapfp.org Joomla Component GMapFP J3.30pro is affected by Insecure Permissions. An attacker can access the upload funct
In Strapi before 3.2.5, there is no admin::hasPermissions restriction for CTB (aka content-type-builder) routes.
In updatePermissions of PermissionManagerService.java, it may be possible for a malicious app to obtain a custom permiss
An issue was discovered in the pricing-table-by-supsystic plugin before 1.8.2 for WordPress. Because there is no permiss
Frequently Asked Questions
What is CWE-276?
CWE-276 (CWE-276) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-276?
There are 1,819 CVE records associated with CWE-276 in our database. Of these, 115 are critical severity, 732 are high severity, and 580 are medium severity.
How can I protect against CWE-276 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-276 using AI-powered security agents.
Detect CWE-276 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-276 vulnerabilities across your infrastructure.
Get Started