CWE-273 · 39 записей
Improper Check for Dropped Privileges
CVE этого класса
39 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2011-2921Готовый эксплойт | ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can resktsuss project · ktsuss · CWE-273 | Критическая9,8 | — | 83,1 % | 19 нояб. 2019 г. |
43В плане | CVE-2017-6972Proof of concept | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl coalienvault · ossim · CWE-273 | Критическая9,8 | — | 14,6 % | 22 мар. 2017 г. |
41В плане | CVE-2015-0278Эксплойта нет | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vefedoraproject · fedora · CWE-273 | Критическая10,0 | — | 3,2 % | 18 мая 2015 г. |
40В плане | CVE-2021-36372Эксплойта нет | Original block tokens are persisted and can be retrievedapache · ozone · CWE-273 | Критическая9,8 | — | 2,5 % | 19 нояб. 2021 г. |
40В плане | CVE-2020-24361Эксплойта нет | SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.snmptt · snmptt · CWE-273 | Критическая9,8 | — | 2,0 % | 16 авг. 2020 г. |
40В плане | CVE-2011-3350Эксплойта нет | masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.marmaro · masqmail · CWE-273 | Критическая9,8 | — | 1,7 % | 19 нояб. 2019 г. |
39Наблюдать | CVE-2012-1187Эксплойта нет | Bitlbee does not drop extra group privileges correctly in unix.cbitlbee · bitlbee · CWE-273 | Критическая9,8 | — | 1,6 % | 29 окт. 2019 г. |
39Наблюдать | CVE-2023-34844Эксплойта нет | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.play with docker project · play with docker · CWE-273 | Критическая9,8 | — | 0,9 % | 29 июн. 2023 г. |
35Наблюдать | CVE-2024-8382Эксплойта нет | Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.mozilla · firefox · CWE-273 | Высокая8,8 | — | 0,6 % | 3 сент. 2024 г. |
35Наблюдать | CVE-2020-14300Эксплойта нет | The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://adocker · docker · CWE-273 | Высокая8,8 | — | 0,4 % | 13 июл. 2020 г. |
35Наблюдать | CVE-2020-14298Эксплойта нет | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc midocker · docker · CWE-273 | Высокая8,8 | — | 0,3 % | 13 июл. 2020 г. |
35Наблюдать | CVE-2026-32107Эксплойта нет | xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid failsneutrinolabs · xrdp · CWE-273 | Высокая8,8 | — | 0,2 % | 17 апр. 2026 г. |
34Наблюдать | CVE-2025-27396Эксплойта нет | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).siemens · scalance lpe9403 firmware · CWE-273 | Высокая8,7 | — | 0,4 % | 11 мар. 2025 г. |
34Наблюдать | CVE-2026-60085Эксплойта нет | PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandboxmervinpraison · praisonai · CWE-273 | Высокая8,7 | — | 0,4 % | 15 июл. 2026 г. |
34Наблюдать | CVE-2025-1003Эксплойта нет | HP Anyware Agent for Linux – Potential Authentication Bypasshp, inc. · hp anyware linux agent · CWE-273 | Высокая8,5 | — | 0,2 % | 3 февр. 2025 г. |
32Наблюдать | CVE-2019-18276Proof of concept | An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.gnu · bash · CWE-273 | Высокая7,8 | — | 2,6 % | 27 нояб. 2019 г. |
32Наблюдать | CVE-2026-58086Эксплойта нет | ktrace(2) privilege incorrectly validated in jailsfreebsd · freebsd · CWE-273 | Высокая8,1 | — | 0,4 % | 19 авг. 2026 г. |
31Наблюдать | CVE-2018-8599Эксплойта нет | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file opermicrosoft · visual studio · CWE-273 | Высокая7,8 | — | 1,0 % | 11 дек. 2018 г. |
31Наблюдать | CVE-2019-20044Эксплойта нет | In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.zsh · zsh · CWE-273 | Высокая7,8 | — | 0,5 % | 24 февр. 2020 г. |
31Наблюдать | CVE-2021-47129Эксплойта нет | netfilter: nft_ct: skip expectations for confirmed conntracklinux · linux kernel · CWE-273 | Высокая7,8 | — | 0,4 % | 15 мар. 2024 г. |
31Наблюдать | CVE-2006-2916Эксплойта нет | artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,linux · linux kernel · CWE-273 | Высокая7,8 | — | 0,4 % | 15 июн. 2006 г. |
31Наблюдать | CVE-2022-0358Эксплойта нет | A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.qemu · qemu · CWE-273 | Высокая7,8 | — | 0,3 % | 29 авг. 2022 г. |
31Наблюдать | CVE-2023-52433Эксплойта нет | netfilter: nft_set_rbtree: skip sync GC for new elements in this transactionlinux · linux kernel · CWE-273 | Высокая7,8 | — | 0,3 % | 20 февр. 2024 г. |
31Наблюдать | CVE-2023-34322Эксплойта нет | top-level shadow reference dropped too early for 64-bit PV guestsxen · xen · CWE-273 | Высокая7,8 | — | 0,2 % | 5 янв. 2024 г. |
31Наблюдать | CVE-2026-54552Эксплойта нет | sh _uid does not drop supplementary groups (incomplete privilege drop)amoffat · sh · CWE-273 | Высокая7,9 | — | 0,2 % | 18 авг. 2026 г. |
- CVE-2011-292164На этой неделе
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can res
КритическаяCVSS 9,8Готовый эксплойтEPSS 83 %ktsuss project · ktsuss19 нояб. 2019 г.
- CVE-2017-697243В плане
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co
КритическаяCVSS 9,8Proof of conceptEPSS 15 %alienvault · ossim22 мар. 2017 г.
- CVE-2015-027841В плане
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified ve
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %fedoraproject · fedora18 мая 2015 г.
- CVE-2021-3637240В плане
Original block tokens are persisted and can be retrieved
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %apache · ozone19 нояб. 2021 г.
- CVE-2020-2436140В плане
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %snmptt · snmptt16 авг. 2020 г.
- CVE-2011-335040В плане
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %marmaro · masqmail19 нояб. 2019 г.
- CVE-2012-118739Наблюдать
Bitlbee does not drop extra group privileges correctly in unix.c
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %bitlbee · bitlbee29 окт. 2019 г.
- CVE-2023-3484439Наблюдать
Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %play with docker project · play with docker29 июн. 2023 г.
- CVE-2024-838235Наблюдать
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mozilla · firefox3 сент. 2024 г.
- CVE-2020-1430035Наблюдать
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://a
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %docker · docker13 июл. 2020 г.
- CVE-2020-1429835Наблюдать
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc mi
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %docker · docker13 июл. 2020 г.
- CVE-2026-3210735Наблюдать
xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %neutrinolabs · xrdp17 апр. 2026 г.
- CVE-2025-2739634Наблюдать
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %siemens · scalance lpe9403 firmware11 мар. 2025 г.
- CVE-2026-6008534Наблюдать
PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %mervinpraison · praisonai15 июл. 2026 г.
- CVE-2025-100334Наблюдать
HP Anyware Agent for Linux – Potential Authentication Bypass
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %hp, inc. · hp anyware linux agent3 февр. 2025 г.
- CVE-2019-1827632Наблюдать
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.
ВысокаяCVSS 7,8Proof of conceptEPSS 3 %gnu · bash27 нояб. 2019 г.
- CVE-2026-5808632Наблюдать
ktrace(2) privilege incorrectly validated in jails
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %freebsd · freebsd19 авг. 2026 г.
- CVE-2018-859931Наблюдать
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file oper
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %microsoft · visual studio11 дек. 2018 г.
- CVE-2019-2004431Наблюдать
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %zsh · zsh24 февр. 2020 г.
- CVE-2021-4712931Наблюдать
netfilter: nft_ct: skip expectations for confirmed conntrack
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linux · linux kernel15 мар. 2024 г.
- CVE-2006-291631Наблюдать
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linux · linux kernel15 июн. 2006 г.
- CVE-2022-035831Наблюдать
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %qemu · qemu29 авг. 2022 г.
- CVE-2023-5243331Наблюдать
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %linux · linux kernel20 февр. 2024 г.
- CVE-2023-3432231Наблюдать
top-level shadow reference dropped too early for 64-bit PV guests
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %xen · xen5 янв. 2024 г.
- CVE-2026-5455231Наблюдать
sh _uid does not drop supplementary groups (incomplete privilege drop)
ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %amoffat · sh18 авг. 2026 г.