İçeriğe atla
Noroxi

CWE-271 · 11 kayıt

Privilege Dropping / Lowering Errors

Bu sınıftaki CVE’ler

11 kayıt

  • CVE-2023-22648
    35İzleyin

    A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they

    YüksekCVSS 8,8İstismar yokEPSS %0

    suse · rancher1 Haz 2023

  • CVE-2024-0985
    33İzleyin

    PostgreSQL non-owner REFRESH MATERIALIZED VIEW CONCURRENTLY executes arbitrary SQL

    YüksekCVSS 8,0İstismar yokEPSS %2

    postgresql · postgresql8 Şub 2024

  • CVE-2019-11243
    32İzleyin

    In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials r

    YüksekCVSS 8,1İstismar yokEPSS %1

    kubernetes · kubernetes22 Nis 2019

  • Kahi has privilege-drop and socket/log permission issues

    YüksekCVSS 8,0İstismar yok

    Go · github.com/kahiteam/kahi30 Haz 2026

  • CVE-2022-3569
    31İzleyin

    Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in version

    YüksekCVSS 7,8SilahlaştırılmışEPSS %1

    synacor · zimbra collaboration suite17 Eki 2022

  • CVE-2026-35535
    31İzleyin

    In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer

    YüksekCVSS 7,8İstismar yokEPSS %0

    sudo project · sudo2 Nis 2026

  • CVE-2025-53819
    31İzleyin

    Nix's privilege dropping to build user broke for macOS

    YüksekCVSS 7,9İstismar yokEPSS %0

    nixos · nix14 Tem 2025

  • CVE-2025-23395
    29İzleyin

    Local root exploit via `logfile_reopen()` in screen 5.0.0 with setuid-root bit set

    YüksekCVSS 7,3İstismar yokEPSS %0

    26 May 2025

  • CVE-2024-35179
    27İzleyin

    Unprivileged Stalwart Mail Server user can read files as root

    OrtaCVSS 6,8İstismar yokEPSS %1

    stalwartlabs · mail-server15 May 2024

  • CVE-2026-25704
    23İzleyin

    Incomplete privilege drop for com.system76.CosmicGreeter.GetUserData

    OrtaCVSS 5,8İstismar yokEPSS %0

    pop-os · cosmic-greeter30 Mar 2026

  • CVE-2020-35513
    19İzleyin

    A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the wa

    OrtaCVSS 4,9İstismar yokEPSS %1

    linux · linux kernel26 Oca 2021

Tüm zafiyet sınıfları