Skip to content
Noroxi

CWE-271 · 11 records

Privilege Dropping / Lowering Errors

CVEs in this class

11 records

  • A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they

    HighCVSS 8.8No exploitEPSS 0%

    suse · rancherJun 1, 2023

  • CVE-2024-0985
    33Monitor

    PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL

    HighCVSS 8.0No exploitEPSS 2%

    postgresql · postgresqlFeb 8, 2024

  • In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials r

    HighCVSS 8.1No exploitEPSS 1%

    kubernetes · kubernetesApr 22, 2019

  • Kahi has privilege-drop and socket/log permission issues

    HighCVSS 8.0No exploit

    Go · github.com/kahiteam/kahiJun 30, 2026

  • CVE-2022-3569
    31Monitor

    Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in version

    HighCVSS 7.8WeaponizedEPSS 1%

    synacor · zimbra collaboration suiteOct 17, 2022

  • In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer

    HighCVSS 7.8No exploitEPSS 0%

    sudo project · sudoApr 2, 2026

  • Nix's privilege dropping to build user broke for macOS

    HighCVSS 7.9No exploitEPSS 0%

    nixos · nixJul 14, 2025

  • Local root exploit via `logfile_reopen()` in screen 5.0.0 with setuid-root bit set

    HighCVSS 7.3No exploitEPSS 0%

    May 26, 2025

  • Unprivileged Stalwart Mail Server user can read files as root

    MediumCVSS 6.8No exploitEPSS 1%

    stalwartlabs · mail-serverMay 15, 2024

  • Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

    MediumCVSS 5.8No exploitEPSS 0%

    pop-os · cosmic-greeterMar 30, 2026

  • A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the wa

    MediumCVSS 4.9No exploitEPSS 1%

    linux · linux kernelJan 26, 2021

All vulnerability classes