Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2022-20611HIGHIn deletePackageVersionedInternal of DeletePackageHelper.java, there is a possible way to bypass carrier restrictions due to a permissions bEPSS 0.1%CVE-2026-82165MEDIUMDell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low pEPSS 0.1%CVE-2026-82163MEDIUMDell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attEPSS 0.1%CVE-2026-58564HIGHDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with lEPSS 0.1%CVE-2024-43086MEDIUMIn validateAccountsInternal of AccountManagerService.java, there is a possible way to leak account credentials to a third party app due to aEPSS 0.1%CVE-2023-21187—In onCreate of UsbAccessoryUriActivity.java, there is a possible way to escape the Setup Wizard due to a logic error in the code. This couldEPSS 0.1%CVE-2026-9634HIGHRedundancy Module Configuration Tool - Multiple VulnerabilitiesEPSS 0.1%CVE-2026-9633HIGHRedundancy Module Configuration Tool - Multiple VulnerabilitiesEPSS 0.1%CVE-2025-48516MEDIUMInsecure default configuration state of DDR5 memory module by AGESA Bootloader Firmware could allow an attacker with local user privilege toEPSS 0.1%CVE-2024-53841HIGHIn startListeningForDeviceStateChanges, there is a possible Permission Bypass due to a confused deputy. This could lead to local escalation EPSS 0.1%CVE-2023-21128—In various functions of AppStandbyController.java, there is a possible way to break manageability scenarios due to a logic error in the codeEPSS 0.1%CVE-2026-50255MEDIUMIncorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploiteEPSS 0.1%CVE-2023-21175—In onCreate of DataUsageSummary.java, there is a possible method for a guest user to enable or disable mobile data due to a permissions bypaEPSS 0.1%CVE-2026-27653MEDIUMThe installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow aEPSS 0.1%CVE-2023-21270HIGHIn restorePermissionState of PermissionManagerServiceImpl.java, there is a possible way for an app to keep permissions that should be revokeEPSS 0.1%CVE-2025-52640MEDIUMHCL AION is affected by multiple security vulnerabilities.EPSS 0.1%CVE-2026-86836HIGHIn Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictaEPSS 0.1%CVE-2023-21126—In bindOutputSwitcherAndBroadcastButton of MediaControlPanel.java, there is a possible launch arbitrary activity under SysUI due to Unsafe IEPSS 0.1%CVE-2023-21107HIGHIn retrieveAppEntry of NotificationAccessDetails.java, there is a missing permission check. This could lead to local escalation of privilegeEPSS 0.1%CVE-2025-31655MEDIUMIncorrect default permissions for some Intel(R) Battery Life Diagnostic Tool within Ring 3: User Applications may allow an escalation of priEPSS 0.1%