Перейти к содержимому
Noroxi

CWE-273 · 39 записей

Improper Check for Dropped Privileges

CVE этого класса

39 записей

  • CVE-2011-2921
    64На этой неделе

    ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can res

    КритическаяCVSS 9,8Готовый эксплойтEPSS 83 %

    ktsuss project · ktsuss19 нояб. 2019 г.

  • CVE-2017-6972
    43В плане

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co

    КритическаяCVSS 9,8Proof of conceptEPSS 15 %

    alienvault · ossim22 мар. 2017 г.

  • CVE-2015-0278
    41В плане

    libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified ve

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    fedoraproject · fedora18 мая 2015 г.

  • CVE-2021-36372
    40В плане

    Original block tokens are persisted and can be retrieved

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    apache · ozone19 нояб. 2021 г.

  • CVE-2020-24361
    40В плане

    SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    snmptt · snmptt16 авг. 2020 г.

  • CVE-2011-3350
    40В плане

    masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    marmaro · masqmail19 нояб. 2019 г.

  • CVE-2012-1187
    39Наблюдать

    Bitlbee does not drop extra group privileges correctly in unix.c

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    bitlbee · bitlbee29 окт. 2019 г.

  • CVE-2023-34844
    39Наблюдать

    Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    play with docker project · play with docker29 июн. 2023 г.

  • CVE-2024-8382
    35Наблюдать

    Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    mozilla · firefox3 сент. 2024 г.

  • CVE-2020-14300
    35Наблюдать

    The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    docker · docker13 июл. 2020 г.

  • CVE-2020-14298
    35Наблюдать

    The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc mi

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    docker · docker13 июл. 2020 г.

  • CVE-2026-32107
    35Наблюдать

    xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    neutrinolabs · xrdp17 апр. 2026 г.

  • CVE-2025-27396
    34Наблюдать

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    siemens · scalance lpe9403 firmware11 мар. 2025 г.

  • CVE-2026-60085
    34Наблюдать

    PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    mervinpraison · praisonai15 июл. 2026 г.

  • CVE-2025-1003
    34Наблюдать

    HP Anyware Agent for Linux – Potential Authentication Bypass

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    hp, inc. · hp anyware linux agent3 февр. 2025 г.

  • CVE-2019-18276
    32Наблюдать

    An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.

    ВысокаяCVSS 7,8Proof of conceptEPSS 3 %

    gnu · bash27 нояб. 2019 г.

  • CVE-2026-58086
    32Наблюдать

    ktrace(2) privilege incorrectly validated in jails

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    freebsd · freebsd19 авг. 2026 г.

  • CVE-2018-8599
    31Наблюдать

    An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file oper

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    microsoft · visual studio11 дек. 2018 г.

  • CVE-2019-20044
    31Наблюдать

    In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    zsh · zsh24 февр. 2020 г.

  • CVE-2021-47129
    31Наблюдать

    netfilter: nft_ct: skip expectations for confirmed conntrack

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    linux · linux kernel15 мар. 2024 г.

  • CVE-2006-2916
    31Наблюдать

    artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    linux · linux kernel15 июн. 2006 г.

  • CVE-2022-0358
    31Наблюдать

    A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    qemu · qemu29 авг. 2022 г.

  • CVE-2023-52433
    31Наблюдать

    netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    linux · linux kernel20 февр. 2024 г.

  • CVE-2023-34322
    31Наблюдать

    top-level shadow reference dropped too early for 64-bit PV guests

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    xen · xen5 янв. 2024 г.

  • CVE-2026-54552
    31Наблюдать

    sh _uid does not drop supplementary groups (incomplete privilege drop)

    ВысокаяCVSS 7,9Эксплойта нетEPSS 0 %

    amoffat · sh18 авг. 2026 г.

Все классы уязвимостей