CWE-273 · 39 kayıt
Improper Check for Dropped Privileges
Bu sınıftaki CVE’ler
39 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
64Bu hafta | CVE-2011-2921Silahlaştırılmış | ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can resktsuss project · ktsuss · CWE-273 | Kritik9,8 | — | %83,1 | 19 Kas 2019 |
43Planlayın | CVE-2017-6972Kavram kanıtı | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl coalienvault · ossim · CWE-273 | Kritik9,8 | — | %14,6 | 22 Mar 2017 |
41Planlayın | CVE-2015-0278İstismar yok | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vefedoraproject · fedora · CWE-273 | Kritik10,0 | — | %3,2 | 18 May 2015 |
40Planlayın | CVE-2021-36372İstismar yok | Original block tokens are persisted and can be retrievedapache · ozone · CWE-273 | Kritik9,8 | — | %2,5 | 19 Kas 2021 |
40Planlayın | CVE-2020-24361İstismar yok | SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.snmptt · snmptt · CWE-273 | Kritik9,8 | — | %2,0 | 16 Ağu 2020 |
40Planlayın | CVE-2011-3350İstismar yok | masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.marmaro · masqmail · CWE-273 | Kritik9,8 | — | %1,7 | 19 Kas 2019 |
39İzleyin | CVE-2012-1187İstismar yok | Bitlbee does not drop extra group privileges correctly in unix.cbitlbee · bitlbee · CWE-273 | Kritik9,8 | — | %1,6 | 29 Eki 2019 |
39İzleyin | CVE-2023-34844İstismar yok | Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.play with docker project · play with docker · CWE-273 | Kritik9,8 | — | %0,9 | 29 Haz 2023 |
35İzleyin | CVE-2024-8382İstismar yok | Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.mozilla · firefox · CWE-273 | Yüksek8,8 | — | %0,6 | 3 Eyl 2024 |
35İzleyin | CVE-2020-14300İstismar yok | The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://adocker · docker · CWE-273 | Yüksek8,8 | — | %0,4 | 13 Tem 2020 |
35İzleyin | CVE-2020-14298İstismar yok | The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc midocker · docker · CWE-273 | Yüksek8,8 | — | %0,3 | 13 Tem 2020 |
35İzleyin | CVE-2026-32107İstismar yok | xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid failsneutrinolabs · xrdp · CWE-273 | Yüksek8,8 | — | %0,2 | 17 Nis 2026 |
34İzleyin | CVE-2025-27396İstismar yok | A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).siemens · scalance lpe9403 firmware · CWE-273 | Yüksek8,7 | — | %0,4 | 11 Mar 2025 |
34İzleyin | CVE-2026-60085İstismar yok | PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandboxmervinpraison · praisonai · CWE-273 | Yüksek8,7 | — | %0,4 | 15 Tem 2026 |
34İzleyin | CVE-2025-1003İstismar yok | HP Anyware Agent for Linux – Potential Authentication Bypasshp, inc. · hp anyware linux agent · CWE-273 | Yüksek8,5 | — | %0,2 | 3 Şub 2025 |
32İzleyin | CVE-2019-18276Kavram kanıtı | An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.gnu · bash · CWE-273 | Yüksek7,8 | — | %2,6 | 27 Kas 2019 |
32İzleyin | CVE-2026-58086İstismar yok | ktrace(2) privilege incorrectly validated in jailsfreebsd · freebsd · CWE-273 | Yüksek8,1 | — | %0,4 | 19 Ağu 2026 |
31İzleyin | CVE-2018-8599İstismar yok | An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file opermicrosoft · visual studio · CWE-273 | Yüksek7,8 | — | %1,0 | 11 Ara 2018 |
31İzleyin | CVE-2019-20044İstismar yok | In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.zsh · zsh · CWE-273 | Yüksek7,8 | — | %0,5 | 24 Şub 2020 |
31İzleyin | CVE-2021-47129İstismar yok | netfilter: nft_ct: skip expectations for confirmed conntracklinux · linux kernel · CWE-273 | Yüksek7,8 | — | %0,4 | 15 Mar 2024 |
31İzleyin | CVE-2006-2916İstismar yok | artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,linux · linux kernel · CWE-273 | Yüksek7,8 | — | %0,4 | 15 Haz 2006 |
31İzleyin | CVE-2022-0358İstismar yok | A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.qemu · qemu · CWE-273 | Yüksek7,8 | — | %0,3 | 29 Ağu 2022 |
31İzleyin | CVE-2023-52433İstismar yok | netfilter: nft_set_rbtree: skip sync GC for new elements in this transactionlinux · linux kernel · CWE-273 | Yüksek7,8 | — | %0,3 | 20 Şub 2024 |
31İzleyin | CVE-2023-34322İstismar yok | top-level shadow reference dropped too early for 64-bit PV guestsxen · xen · CWE-273 | Yüksek7,8 | — | %0,2 | 5 Oca 2024 |
31İzleyin | CVE-2026-54552İstismar yok | sh _uid does not drop supplementary groups (incomplete privilege drop)amoffat · sh · CWE-273 | Yüksek7,9 | — | %0,2 | 18 Ağu 2026 |
- CVE-2011-292164Bu hafta
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can res
KritikCVSS 9,8SilahlaştırılmışEPSS %83ktsuss project · ktsuss19 Kas 2019
- CVE-2017-697243Planlayın
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl co
KritikCVSS 9,8Kavram kanıtıEPSS %15alienvault · ossim22 Mar 2017
- CVE-2015-027841Planlayın
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified ve
KritikCVSS 10,0İstismar yokEPSS %3fedoraproject · fedora18 May 2015
- CVE-2021-3637240Planlayın
Original block tokens are persisted and can be retrieved
KritikCVSS 9,8İstismar yokEPSS %3apache · ozone19 Kas 2021
- CVE-2020-2436140Planlayın
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
KritikCVSS 9,8İstismar yokEPSS %2snmptt · snmptt16 Ağu 2020
- CVE-2011-335040Planlayın
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
KritikCVSS 9,8İstismar yokEPSS %2marmaro · masqmail19 Kas 2019
- CVE-2012-118739İzleyin
Bitlbee does not drop extra group privileges correctly in unix.c
KritikCVSS 9,8İstismar yokEPSS %2bitlbee · bitlbee29 Eki 2019
- CVE-2023-3484439İzleyin
Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape.
KritikCVSS 9,8İstismar yokEPSS %1play with docker project · play with docker29 Haz 2023
- CVE-2024-838235İzleyin
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.
YüksekCVSS 8,8İstismar yokEPSS %1mozilla · firefox3 Eyl 2024
- CVE-2020-1430035İzleyin
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://a
YüksekCVSS 8,8İstismar yokEPSS %0docker · docker13 Tem 2020
- CVE-2020-1429835İzleyin
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc mi
YüksekCVSS 8,8İstismar yokEPSS %0docker · docker13 Tem 2020
- CVE-2026-3210735İzleyin
xrdp: Fail-open privilege drop in sesexec — child processes may execute as root if setuid fails
YüksekCVSS 8,8İstismar yokEPSS %0neutrinolabs · xrdp17 Nis 2026
- CVE-2025-2739634İzleyin
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0).
YüksekCVSS 8,7İstismar yokEPSS %0siemens · scalance lpe9403 firmware11 Mar 2025
- CVE-2026-6008534İzleyin
PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox
YüksekCVSS 8,7İstismar yokEPSS %0mervinpraison · praisonai15 Tem 2026
- CVE-2025-100334İzleyin
HP Anyware Agent for Linux – Potential Authentication Bypass
YüksekCVSS 8,5İstismar yokEPSS %0hp, inc. · hp anyware linux agent3 Şub 2025
- CVE-2019-1827632İzleyin
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.
YüksekCVSS 7,8Kavram kanıtıEPSS %3gnu · bash27 Kas 2019
- CVE-2026-5808632İzleyin
ktrace(2) privilege incorrectly validated in jails
YüksekCVSS 8,1İstismar yokEPSS %0freebsd · freebsd19 Ağu 2026
- CVE-2018-859931İzleyin
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file oper
YüksekCVSS 7,8İstismar yokEPSS %1microsoft · visual studio11 Ara 2018
- CVE-2019-2004431İzleyin
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.
YüksekCVSS 7,8İstismar yokEPSS %0zsh · zsh24 Şub 2020
- CVE-2021-4712931İzleyin
netfilter: nft_ct: skip expectations for confirmed conntrack
YüksekCVSS 7,8İstismar yokEPSS %0linux · linux kernel15 Mar 2024
- CVE-2006-291631İzleyin
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call,
YüksekCVSS 7,8İstismar yokEPSS %0linux · linux kernel15 Haz 2006
- CVE-2022-035831İzleyin
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation.
YüksekCVSS 7,8İstismar yokEPSS %0qemu · qemu29 Ağu 2022
- CVE-2023-5243331İzleyin
netfilter: nft_set_rbtree: skip sync GC for new elements in this transaction
YüksekCVSS 7,8İstismar yokEPSS %0linux · linux kernel20 Şub 2024
- CVE-2023-3432231İzleyin
top-level shadow reference dropped too early for 64-bit PV guests
YüksekCVSS 7,8İstismar yokEPSS %0xen · xen5 Oca 2024
- CVE-2026-5455231İzleyin
sh _uid does not drop supplementary groups (incomplete privilege drop)
YüksekCVSS 7,9İstismar yokEPSS %0amoffat · sh18 Ağu 2026