CWE-264
1,421 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 21 of 29
- CVE-2016-8446HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Hi…
- CVE-2016-8447HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Hi…
- CVE-2016-8448HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Hi…
- CVE-2016-8449HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a pr…
- CVE-2016-8450HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8451HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compro…
- CVE-2016-8452HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8453HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8454HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8455HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8456HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8457HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8458HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compro…
- CVE-2016-8464HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromis…
- CVE-2016-8465HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromis…
- CVE-2016-8466HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromis…
- CVE-2016-8467MEDIUMCVSS 5.5EG 5.52017-01-13
An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperabili…
- CVE-2016-8468HIGHCVSS 7.0EG 7.02017-01-12
An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a pri…
- CVE-2016-8476HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8479HIGHCVSS 7.8EG 7.82017-03-08
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-8480HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High bec…
- CVE-2016-8481HIGHCVSS 7.0EG 7.02017-02-08
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising …
- CVE-2016-8482HIGHCVSS 7.8EG 7.82018-04-05
An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.
- CVE-2016-8484CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823575.
- CVE-2016-8487CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823724.
- CVE-2016-8488CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.
- CVE-2016-8493HIGHCVSS 8.8EG 8.82017-06-26
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
- CVE-2016-8494HIGHCVSS 7.2EG 7.22017-02-09
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.
- CVE-2016-8501MEDIUMCVSS 5.3EG 5.32016-10-26
Security WiFi bypass in Yandex Browser from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected wi-fi networks despite of special security mechanism is enabled.
- CVE-2016-8528HIGHCVSS 8.8EG 8.82018-02-15
A Remote Escalation of Privilege vulnerability in HPE Helion Eucalyptus version 3.3.0 through 4.3.1 was found.
- CVE-2016-8533HIGHCVSS 8.8EG 8.82018-02-15
A remote priviledge escalation vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- CVE-2016-8534HIGHCVSS 8.8EG 8.82018-02-15
A remote privilege elevation vulnerability in HPE Matrix Operating Environment version 7.6 was found.
- CVE-2016-8561MEDIUMCVSS 6.6EG 6.62016-11-18
A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Users with elevated privileges to TIA-Portal and project data on the engineering station could possibly get p…
- CVE-2016-8585HIGHCVSS 8.8EG 8.82017-04-28
admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.
- CVE-2016-8586HIGHCVSS 8.8EG 8.82017-04-28
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
- CVE-2016-8589HIGHCVSS 8.8EG 8.82017-04-28
log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
- CVE-2016-8590HIGHCVSS 8.8EG 8.82017-04-28
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
- CVE-2016-8591HIGHCVSS 8.8EG 8.82017-04-28
log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
- CVE-2016-8592HIGHCVSS 8.8EG 8.82017-04-28
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.
- CVE-2016-8600HIGHCVSS 7.5EG 7.52016-10-28
In dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check later.
- CVE-2016-8629MEDIUMCVSS 6.5EG 6.52018-03-12
Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal pe…
- CVE-2016-8632HIGHCVSS 7.8EG 7.82016-11-28
The tipc_msg_build function in net/tipc/msg.c in the Linux kernel through 4.8.11 does not validate the relationship between the minimum fragment length and the maximum packet size, which allows local users to gain privileges or cause a den…
- CVE-2016-8644MEDIUMCVSS 5.3EG 5.32017-01-20
In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.
- CVE-2016-8649CRITICALCVSS 9.1EG 9.12017-05-01
lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inherited file descriptor, of the host's /proc, to access the rest of the host's filesystem via the openat() family of sys…
- CVE-2016-8656HIGHCVSS 7.0EG 7.82018-05-22
Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local privilege escalation.
- CVE-2016-8657HIGHCVSS 7.8EG 7.82018-07-31
It was discovered that EAP packages in certain versions of Red Hat Enterprise Linux use incorrect permissions for /etc/sysconfig/jbossas configuration files. The file is writable to jboss group (root:jboss, 664). On systems using classic /…
- CVE-2016-8659HIGHCVSS 7.0EG 7.02017-02-13
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.
- CVE-2016-8742HIGHCVSS 7.8EG 7.82018-02-12
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any …
- CVE-2016-8769MEDIUMCVSS 6.7EG 6.72017-04-02
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected servi…
- CVE-2016-8803HIGHCVSS 7.5EG 7.52017-04-02
The maintenance module in Huawei FusionStorage V100R003C30U1 allows attackers to create documents according to special rules to obtain the OS root privilege of FusionStorage.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →