CWE-269— Improper Privilege Management
4,215 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 2 of 85
- CVE-2013-4583HIGHCVSS 8.8EG 8.82020-01-28
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbi…
- CVE-2013-4867MEDIUMCVSS 6.3EG 6.32019-12-27
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
- CVE-2013-4975HIGHCVSS 8.8EG 8.82019-12-27
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
- CVE-2013-5027CRITICALCVSS 9.8EG 9.82019-12-27
Collabtive 1.0 has incorrect access control
- CVE-2013-6231HIGHCVSS 8.8EG 8.82020-01-10
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
- CVE-2013-6295CRITICALCVSS 9.8EG 9.82020-02-18
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
- CVE-2013-6391NONECVSS 0.0EG 0.02013-12-14
The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 creden…
- CVE-2013-6773HIGHCVSS 7.8EG 7.82020-01-23
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
- CVE-2013-7421NONECVSS 0.0EG 0.02015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
- CVE-2014-0185NONECVSS 0.0EG 0.02014-05-06
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI client.
- CVE-2014-125001HIGHCVSS 8.1EG 8.82022-05-24
A vulnerability classified as critical has been found in Cardo Systems Scala Rider Q3. Affected is the file /cardo/api of the Cardo-Updater. Unauthenticated remote code execution with root permissions is possible. Firewalling or disabling …
- CVE-2014-1496MEDIUMCVSS 5.5EG 5.52014-03-19
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
- CVE-2014-1520NONECVSS 0.0EG 0.02014-04-30
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary director…
- CVE-2014-1526NONECVSS 0.0EG 0.02014-04-30
The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapp…
- CVE-2014-1529HIGHCVSS 8.8EG 8.82014-04-30
The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaSc…
- CVE-2014-3153HIGHCVSS 7.8EG 9.0⚠ KEV2014-06-07
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates…
- CVE-2014-3534NONECVSS 0.0EG 0.02014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kerne…
- CVE-2014-3689NONECVSS 0.0EG 0.02014-11-14
The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling.
- CVE-2014-4170CRITICALCVSS 9.8EG 9.82020-02-13
A Privilege Escalation Vulnerability exists in Free Reprintables ArticleFR 11.06.2014 due to insufficient access restrictions in the data.php script, which could let a remote malicious user obtain access or modify or delete database inform…
- CVE-2014-4943NONECVSS 0.0EG 0.02014-07-19
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket.
- CVE-2014-5206NONECVSS 0.0EG 0.02014-08-18
The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restriction and defeat cert…
- CVE-2014-5207NONECVSS 0.0EG 0.02014-08-18
fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfer…
- CVE-2014-6448HIGHCVSS 7.8EG 7.82020-01-15
Juniper Junos OS 13.2 before 13.2R5, 13.2X51, 13.2X52, and 13.3 before 13.3R3 allow local users to bypass intended restrictions and execute arbitrary Python code via vectors involving shell access.
- CVE-2014-9193NONECVSS 0.0EG 0.02014-12-20
Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.
- CVE-2014-9322HIGHCVSS 7.8EG 7.82014-12-17
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads …
- CVE-2014-9644NONECVSS 0.0EG 0.02015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the…
- CVE-2015-0192CRITICALCVSS 9.8EG 0.02015-07-02
Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors related to the Java Vir…
- CVE-2015-0239NONECVSS 0.0EG 0.02015-03-02
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by t…
- CVE-2015-0949HIGHCVSS 7.8EG 7.82020-01-30
The System Management Mode (SMM) implementation in Dell Latitude E6430 BIOS Revision A09, HP EliteBook 850 G1 BIOS revision L71 Ver. 01.09, and possibly other BIOS implementations does not ensure that function calls operate on SMRAM memory…
- CVE-2015-10139HIGHCVSS 8.8EG 8.82025-07-19
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and pote…
- CVE-2015-2909CRITICALCVSS 9.8EG 9.82020-02-06
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote attackers to obtain access by leveraging …
- CVE-2015-3613CRITICALCVSS 9.8EG 9.82020-02-04
A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page
- CVE-2015-4719CRITICALCVSS 9.8EG 9.82020-09-24
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
- CVE-2015-5071MEDIUMCVSS 6.5EG 6.52020-01-15
AR System Mid Tier in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary files via the __report parameter of the BIRT viewer servlet.
- CVE-2015-5072MEDIUMCVSS 6.5EG 6.52020-01-15
The BIRT Engine servlet in the AR System Mid Tier component before 9.0 SP1 for BMC Remedy AR System Server allows remote authenticated users to "navigate" to arbitrary local files via the __imageid parameter.
- CVE-2015-5466HIGHCVSS 7.8EG 7.82020-01-15
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.
- CVE-2015-7333HIGHCVSS 7.8EG 7.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where th…
- CVE-2015-7334HIGHCVSS 7.8EG 7.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where th…
- CVE-2015-7556HIGHCVSS 7.8EG 7.82020-01-15
DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.
- CVE-2015-7831HIGHCVSS 8.8EG 8.82019-11-26
In Cloudera Hue, there is privilege escalation by a read-only user when CDH 5.x brefore 5.4.9 is used.
- CVE-2015-8032MEDIUMCVSS 5.3EG 5.32020-08-14
In Textpattern 4.5.7, an unprivileged author can change an article's markup setting.
- CVE-2015-8534HIGHCVSS 7.8EG 7.82020-03-27
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed and publicly disclosed in 2015) in Lenovo Solution Center (LSC) prior to version 3.3.002 t…
- CVE-2015-9267MEDIUMCVSS 5.5EG 5.52018-10-01
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Troja…
- CVE-2015-9390MEDIUMCVSS 4.3EG 4.32019-09-20
The admin-management-xtended plugin before 2.4.0.1 for WordPress has privilege escalation because wp_ajax functions are mishandled.
- CVE-2016-0151HIGHCVSS 7.8EG 9.0⚠ KEV2016-04-12
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted appli…
- CVE-2016-10010HIGHCVSS 7.0EG 7.02017-01-05
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.
- CVE-2016-10585HIGHCVSS 8.1EG 8.12018-06-01
libxl provides Node bindings for the libxl library for reading and writing excel (XLS and XLSX) spreadsheets. libxl downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code e…
- CVE-2016-10593HIGHCVSS 8.1EG 8.12018-05-29
ibapi is an Interactive Brokers API addon for NodeJS. ibapi downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. Before 2.5.6, it may be possible to cause remote code execution (RCE) by swapping out the request…
- CVE-2016-10594HIGHCVSS 8.1EG 5.92018-06-01
ipip is a Node.js module to query geolocation information for an IP or domain, based on database by ipip.net. ipip downloads data resources over HTTP, which leaves it vulnerable to MITM attacks.
- CVE-2016-10597MEDIUMCVSS 5.9EG 5.92018-06-01
cobalt-cli downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →