İçeriğe atla
Noroxi

CWE-273 · 39 kayıt

Improper Check for Dropped Privileges

Bu sınıftaki CVE’ler

39 kayıt

  • CVE-2011-2921
    64Bu hafta

    ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can res

    KritikCVSS 9,8SilahlaştırılmışEPSS %83

    ktsuss project · ktsuss19 Kas 2019

  • CVE-2017-6972
    43Planlayın

    AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co

    KritikCVSS 9,8Kavram kanıtıEPSS %15

    alienvault · ossim22 Mar 2017

  • CVE-2015-0278
    41Planlayın

    libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified ve

    KritikCVSS 10,0İstismar yokEPSS %3

    fedoraproject · fedora18 May 2015

  • CVE-2021-36372
    40Planlayın

    Original block tokens are persisted and can be retrieved

    KritikCVSS 9,8İstismar yokEPSS %3

    apache · ozone19 Kas 2021

  • CVE-2020-24361
    40Planlayın

    SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.

    KritikCVSS 9,8İstismar yokEPSS %2

    snmptt · snmptt16 Ağu 2020

  • CVE-2011-3350
    40Planlayın

    masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.

    KritikCVSS 9,8İstismar yokEPSS %2

    marmaro · masqmail19 Kas 2019

  • CVE-2012-1187
    39İzleyin

    Bitlbee does not drop extra group privileges correctly in unix.c

    KritikCVSS 9,8İstismar yokEPSS %2

    bitlbee · bitlbee29 Eki 2019

  • CVE-2023-34844
    39İzleyin

    Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.

    KritikCVSS 9,8İstismar yokEPSS %1

    play with docker project · play with docker29 Haz 2023

  • CVE-2024-8382
    35İzleyin

    Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.

    YüksekCVSS 8,8İstismar yokEPSS %1

    mozilla · firefox3 Eyl 2024

  • CVE-2020-14300
    35İzleyin

    The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://a

    YüksekCVSS 8,8İstismar yokEPSS %0

    docker · docker13 Tem 2020

  • CVE-2020-14298
    35İzleyin

    The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc mi

    YüksekCVSS 8,8İstismar yokEPSS %0

    docker · docker13 Tem 2020

  • CVE-2026-32107
    35İzleyin

    xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails

    YüksekCVSS 8,8İstismar yokEPSS %0

    neutrinolabs · xrdp17 Nis 2026

  • CVE-2025-27396
    34İzleyin

    A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).

    YüksekCVSS 8,7İstismar yokEPSS %0

    siemens · scalance lpe9403 firmware11 Mar 2025

  • CVE-2026-60085
    34İzleyin

    PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox

    YüksekCVSS 8,7İstismar yokEPSS %0

    mervinpraison · praisonai15 Tem 2026

  • CVE-2025-1003
    34İzleyin

    HP Anyware Agent for Linux – Potential Authentication Bypass

    YüksekCVSS 8,5İstismar yokEPSS %0

    hp, inc. · hp anyware linux agent3 Şub 2025

  • CVE-2019-18276
    32İzleyin

    An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.

    YüksekCVSS 7,8Kavram kanıtıEPSS %3

    gnu · bash27 Kas 2019

  • CVE-2026-58086
    32İzleyin

    ktrace(2) privilege incorrectly validated in jails

    YüksekCVSS 8,1İstismar yokEPSS %0

    freebsd · freebsd19 Ağu 2026

  • CVE-2018-8599
    31İzleyin

    An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file oper

    YüksekCVSS 7,8İstismar yokEPSS %1

    microsoft · visual studio11 Ara 2018

  • CVE-2019-20044
    31İzleyin

    In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.

    YüksekCVSS 7,8İstismar yokEPSS %0

    zsh · zsh24 Şub 2020

  • CVE-2021-47129
    31İzleyin

    netfilter: nft_ct: skip expectations for confirmed conntrack

    YüksekCVSS 7,8İstismar yokEPSS %0

    linux · linux kernel15 Mar 2024

  • CVE-2006-2916
    31İzleyin

    artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,

    YüksekCVSS 7,8İstismar yokEPSS %0

    linux · linux kernel15 Haz 2006

  • CVE-2022-0358
    31İzleyin

    A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.

    YüksekCVSS 7,8İstismar yokEPSS %0

    qemu · qemu29 Ağu 2022

  • CVE-2023-52433
    31İzleyin

    netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction

    YüksekCVSS 7,8İstismar yokEPSS %0

    linux · linux kernel20 Şub 2024

  • CVE-2023-34322
    31İzleyin

    top-level shadow reference dropped too early for 64-bit PV guests

    YüksekCVSS 7,8İstismar yokEPSS %0

    xen · xen5 Oca 2024

  • CVE-2026-54552
    31İzleyin

    sh _uid does not drop supplementary groups (incomplete privilege drop)

    YüksekCVSS 7,9İstismar yokEPSS %0

    amoffat · sh18 Ağu 2026

Tüm zafiyet sınıfları