VYPR

CWE-274

Improper Handling of Insufficient Privileges

BaseDraft

Description

The product does not handle or incorrectly handles when it has insufficient privileges to perform an operation, leading to resultant weaknesses.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (42)

page 1 of 3
  • CVE-2025-29365CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

  • CVE-2025-20156CriJan 22, 2025
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API…

  • CVE-2024-0105HigNov 1, 2024
    risk 0.58cvss 8.9epss 0.00

    NVIDIA ConnectX Firmware contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and limited information disclosure.

  • CVE-2024-0106HigNov 1, 2024
    risk 0.57cvss 8.7epss 0.00

    NVIDIA ConnectX Host Firmware for the BlueField Data Processing Unit (DPU) contains a vulnerability where an attacker may cause an improper handling of insufficient privileges issue. A successful exploit of this vulnerability may lead to denial of service, data tampering, and…

  • CVE-2020-7267HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended…

  • CVE-2020-7266HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an…

  • CVE-2020-7265HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Mac prior to 10.6.9 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved…

  • CVE-2020-7264HigMay 8, 2020
    risk 0.57cvss 8.8epss 0.00

    Privilege Escalation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 Hotfix 199847 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file.…

  • CVE-2024-46974HigJan 31, 2025
    risk 0.51cvss 7.8epss 0.00

    Software installed and run as a non-privileged user may conduct improper read/write operations on imported/exported DMA buffers.

  • CVE-2020-24676HigDec 22, 2020
    risk 0.51cvss 7.8epss 0.00

    In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.

  • CVE-2020-7291HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Mac prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7290HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Linux prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7289HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Active Response (MAR) for Windows prior to 2.4.3 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7288HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Mac prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7287HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Linux prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7286HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee Exploit Detection and Response (EDR) for Windows prior to 3.1.0 Hotfix 1 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2020-7285HigMay 8, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in McAfee MVISION Endpoint prior to 20.5.0.94 allows a malicious script or program to perform functions that the local executing user has not been granted access to.

  • CVE-2023-39375HigSep 27, 2023
    risk 0.49cvss 7.5epss 0.01

    SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges

  • CVE-2020-7283HigJul 3, 2020
    risk 0.49cvss 7.5epss 0.01

    Privilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link manipulation in a location they would otherwise not have access to. This is achieved through running a malicious script or program on…

  • CVE-2022-45101HigFeb 1, 2023
    risk 0.48cvss 7.3epss 0.01

    Dell PowerScale OneFS 9.0.0.x - 9.4.0.x, contains an Improper Handling of Insufficient Privileges vulnerability in NFS. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure and remote execution.