CWE-269— Improper Privilege Management
4,215 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 1 of 85
- CVE-1999-0084HIGHCVSS 8.4EG 8.41990-05-01
Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.
- CVE-2002-0049NONECVSS 0.0EG 0.02002-03-08
Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
- CVE-2002-0080NONECVSS 0.0EG 0.02002-03-15
rsync, when running in daemon mode, does not properly call setgroups before dropping privileges, which could provide supplemental group privileges to local users, who could then read certain files that would otherwise be disallowed.
- CVE-2002-0367HIGHCVSS 7.8EG 9.0⚠ KEV2002-06-25
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges by duplicating a handle to a privileged…
- CVE-2003-5001MEDIUMCVSS 5.3EG 9.82022-03-28
A vulnerability was found in ISS BlackICE PC Protection and classified as critical. Affected by this issue is the component Cross Site Scripting Detection. The manipulation as part of POST/PUT/DELETE/OPTIONS Request leads to privilege esca…
- CVE-2004-1349NONECVSS 0.0EG 0.02004-10-04
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
- CVE-2006-4243CRITICALCVSS 9.8EG 9.82019-11-06
linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code.
- CVE-2007-2444NONECVSS 0.0EG 0.02007-05-14
Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and execute SMB/CIFS protocol operations via unspecified vectors that cause the daemon to tra…
- CVE-2008-2271NONECVSS 0.0EG 0.02008-05-16
The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the…
- CVE-2008-2931HIGHCVSS 7.8EG 7.82008-07-09
The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a denial of service by modifying the pro…
- CVE-2009-0080NONECVSS 0.0EG 0.02009-04-15
The ThreadPool class in Windows Vista Gold and SP1, and Server 2008, does not properly implement isolation among a set of distinct processes that (1) all run under the NetworkService account or (2) all run under the LocalService account, w…
- CVE-2009-2848NONECVSS 0.0EG 0.02009-08-18
The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges v…
- CVE-2010-3301NONECVSS 0.0EG 0.02010-09-22
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is used, which allows …
- CVE-2010-4258NONECVSS 0.0EG 0.02010-12-30
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, a…
- CVE-2010-4347NONECVSS 0.0EG 0.02010-12-22
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acp…
- CVE-2010-4664HIGHCVSS 8.8EG 8.82019-11-13
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
- CVE-2011-1526NONECVSS 0.0EG 0.02011-07-11
ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, a…
- CVE-2011-2910MEDIUMCVSS 6.7EG 6.72019-11-15
The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fails the daemon would continue to run with root privileges whi…
- CVE-2011-3054NONECVSS 0.0EG 0.02012-03-22
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
- CVE-2011-3349HIGHCVSS 7.8EG 7.82019-11-19
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
- CVE-2011-3898NONECVSS 0.0EG 0.02011-11-11
Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a crafted applet.
- CVE-2011-4954HIGHCVSS 7.8EG 7.82019-11-19
cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE
- CVE-2012-0384HIGHCVSS 7.2EG 7.22012-03-29
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA authorization is enabled…
- CVE-2012-10022HIGHCVSS 8.5EG 0.02025-08-01
Kloxo versions 6.1.12 and earlier contain two setuid root binaries—lxsuexec and lxrestart—that allow local privilege escalation from uid 48. The lxsuexec binary performs a uid check and permits execution of arbitrary commands as root i…
- CVE-2012-1104MEDIUMCVSS 5.3EG 5.32019-12-05
A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed.
- CVE-2012-1563HIGHCVSS 7.5EG 7.52020-01-15
Joomla! before 2.5.3 allows Admin Account Creation.
- CVE-2012-1615HIGHCVSS 7.8EG 7.82019-12-06
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
- CVE-2012-2148LOWCVSS 3.3EG 3.32019-12-06
An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies
- CVE-2012-2312HIGHCVSS 7.8EG 7.82019-12-18
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process …
- CVE-2012-3993NONECVSS 0.0EG 0.02012-10-10
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly interact with failures …
- CVE-2012-4480HIGHCVSS 7.8EG 7.82019-12-02
mom creates world-writable pid files in /var/run
- CVE-2012-4606HIGHCVSS 7.8EG 7.82020-01-23
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain …
- CVE-2012-4760HIGHCVSS 7.8EG 7.82020-01-13
A Privilege Escalation vulnerability exists in the SDBagent service in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges.
- CVE-2012-4761HIGHCVSS 7.8EG 7.82020-01-13
A Privilege Escalation vulnerability exists in the unquoted Service Binary in SDPAgent or SDBAgent in Safend Data Protector Agent 3.4.5586.9772, which could let a local malicious user obtain privileges.
- CVE-2012-4767MEDIUMCVSS 6.1EG 6.12020-01-13
An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious user decrypt and potentially change the Safend security policies applied to the machine.
- CVE-2012-5376CRITICALCVSS 9.6EG 9.62012-10-11
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer process, a different …
- CVE-2012-5617HIGHCVSS 7.8EG 7.82019-11-25
gksu-polkit: permissive PolicyKit policy configuration file allows privilege escalation
- CVE-2012-5663HIGHCVSS 7.5EG 7.52019-12-30
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
- CVE-2012-6302HIGHCVSS 7.8EG 7.82020-01-24
Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
- CVE-2012-6639HIGHCVSS 8.8EG 8.82019-11-25
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
- CVE-2013-0293HIGHCVSS 7.8EG 7.82019-12-10
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
- CVE-2013-0643HIGHCVSS 8.8EG 9.0⚠ KEV2013-02-27
The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, which makes it easier f…
- CVE-2013-10052HIGHCVSS 8.5EG 0.02025-08-04
ZPanel includes a helper binary named zsudo, intended to allow restricted privilege escalation for administrative tasks. However, when misconfigured in /etc/sudoers, zsudo can be invoked by low-privileged users to execute arbitrary comman…
- CVE-2013-2012HIGHCVSS 7.3EG 7.32019-10-31
autojump before 21.5.8 allows local users to gain privileges via a Trojan horse custom_install directory in the current working directory.
- CVE-2013-2016HIGHCVSS 7.8EG 7.82019-12-30
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user…
- CVE-2013-2625MEDIUMCVSS 6.5EG 6.52019-11-27
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
- CVE-2013-3323CRITICALCVSS 9.8EG 9.82020-02-18
A Privilege Escalation Vulnerability exists in IBM Maximo Asset Management 7.5, 7.1, and 6.2, when WebSeal with Basic Authentication is used, due to a failure to invalidate the authentication session, which could let a malicious user obtai…
- CVE-2013-4161HIGHCVSS 7.8EG 7.82019-12-31
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
- CVE-2013-4251HIGHCVSS 7.8EG 7.82019-11-04
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
- CVE-2013-4536HIGHCVSS 7.8EG 7.82021-05-28
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →