VYPR

CWE-269

Improper Privilege Management

ClassDraftLikelihood: Medium

Description

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-122 · CAPEC-233 · CAPEC-58

CVEs mapped to this weakness (3,702)

page 184 of 186
  • CVE-2022-31039MedJun 27, 2022
    risk 0.00cvss 4.3epss 0.01

    Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has…

  • CVE-2022-2023CriJun 20, 2022
    risk 0.00cvss 9.8epss 0.03

    Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

  • CVE-2022-1770HigMay 20, 2022
    risk 0.00cvss 8.8epss 0.03

    Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

  • CVE-2022-1227HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.04

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the…

  • CVE-2022-24842HigApr 12, 2022
    risk 0.00cvss 8.8epss 0.02

    MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. A security issue was found where an non-admin user is able to create service accounts for root or other admin users and then is able to assume their access policies via the…

  • CVE-2022-24750HigMar 10, 2022
    risk 0.00cvss 8.8epss 0.00

    UltraVNC is a free and open source remote pc access software. A vulnerability has been found in versions prior to 1.3.8.0 in which the DSM plugin module, which allows a local authenticated user to achieve local privilege escalation (LPE) on a vulnerable system. The vulnerability…

  • CVE-2022-25636HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.03

    net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.

  • CVE-2022-25372HigFeb 20, 2022
    risk 0.00cvss 7.8epss 0.01

    Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go.

  • CVE-2022-23604HigFeb 15, 2022
    risk 0.00cvss 8.8epss 0.01

    x26-Cogs is a repository of cogs made by Twentysix for the Red Discord bot. Among these cogs is the Defender cog, a tool for Discord server moderation. A vulnerability in the Defender cog prior to version 1.10.0 allows users with admin privileges to issue commands as other users…

  • CVE-2022-23117HigJan 12, 2022
    risk 0.00cvss 7.5epss 0.01

    Jenkins Conjur Secrets Plugin 1.0.9 and earlier implements functionality that allows attackers able to control agent processes to retrieve all username/password credentials stored on the Jenkins controller.

  • CVE-2015-5106Jul 15, 2015
    risk 0.00cvss —epss 0.04

    Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and…

  • CVE-2015-5090Jul 15, 2015
    risk 0.00cvss —epss 0.01

    Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and…

  • CVE-2015-4446Jul 15, 2015
    risk 0.00cvss —epss 0.05

    Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access restrictions and…

  • CVE-2015-0239Mar 2, 2015
    risk 0.00cvss —epss 0.01

    The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment…

  • CVE-2014-9644Mar 2, 2015
    risk 0.00cvss —epss 0.01

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different…

  • CVE-2013-7421Mar 2, 2015
    risk 0.00cvss —epss 0.01

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

  • CVE-2014-9193Dec 20, 2014
    risk 0.00cvss —epss 0.03

    Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.

  • CVE-2014-3689Nov 14, 2014
    risk 0.00cvss —epss 0.00

    The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.

  • CVE-2014-0204Nov 3, 2014
    risk 0.00cvss —epss 0.01

    OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a group with the same ID.

  • CVE-2014-5207Aug 18, 2014
    risk 0.00cvss —epss 0.01

    fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups and auditing on systems…