Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2025-20087MEDIUMIncorrect default permissions for some Intel(R) oneAPI DPC++/C++ Compiler software installers may allow an authenticated user to potentiallyEPSS 0.1%CVE-2025-27559MEDIUMIncorrect default permissions for some AI Playground software before version v2.3.0 alpha may allow an authenticated user to potentially enaEPSS 0.1%CVE-2025-20023MEDIUMIncorrect default permissions for some Intel(R) Graphics Driver software installers may allow an authenticated user to potentially enable esEPSS 0.1%CVE-2025-26470MEDIUMIncorrect default permissions for some Intel(R) Distribution for Python software installers before version 2025.1.0 may allow an authenticatEPSS 0.1%CVE-2024-40660HIGHIn setTransactionState of SurfaceFlinger.cpp, there is a possible way to change protected display attributes due to a logic error in the codEPSS 0.1%CVE-2026-28717MEDIUMLocal privilege escalation due to improper directory permissions. The following products are affected: Acronis Cyber Protect 17 (Windows) beEPSS 0.1%CVE-2022-20448MEDIUMIn buzzBeepBlinkLocked of NotificationManagerService.java, there is a possible way to share data across users due to a permissions bypass. TEPSS 0.1%CVE-2025-36511MEDIUMIncorrect default permissions for some Intel(R) Memory and Storage Tool before version 2.5.2 within Ring 3: User Applications may allow an eEPSS 0.1%CVE-2025-57851MEDIUMMce: privilege escalation via excessive /etc/passwd permissionsEPSS 0.1%CVE-2025-53919HIGHAn issue was discovered in the Portrait Dell Color Management application through 3.3.008 for Dell monitors, It creates a temporary folder, EPSS 0.1%CVE-2025-48505HIGHWeak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged eEPSS 0.1%CVE-2025-32453MEDIUMIncorrect default permissions for some Intel(R) Graphics Driver software within Ring 2: Privileged Process may allow an escalation of privilEPSS 0.1%CVE-2026-39454HIGHSKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission setEPSS 0.1%CVE-2024-43085HIGHIn handleMessage of UsbDeviceManager.java, there is a possible method to access device contents over USB without unlocking the device due toEPSS 0.1%CVE-2021-47761HIGHMilleGPG5 5.7.2 Luglio 2021 (x64) - Local Privilege EscalationEPSS 0.1%CVE-2025-59485MEDIUMIncorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerability is exploited, an EPSS 0.1%CVE-2025-27246MEDIUMIncorrect default permissions for the Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may aEPSS 0.1%CVE-2026-2026MEDIUMImproper Access Control Allows Denial of ServiceEPSS 0.1%CVE-2025-53947MEDIUMCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Default PermissionsEPSS 0.1%CVE-2026-63425HIGHDuring an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could alloEPSS 0.1%