CWE-250

Medium likelihood

Execution with Unnecessary Privileges

Parent: CWE-269 - Improper Privilege Management

The product performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.

341 vulnerabilities with CWE-250
CVE-2019-10167 HIGH
libvirt <4.10.1-5.4.1 - Code Injection
CVSS 7.8
CVE-2019-10147 HIGH
rkt < 1.30.0 - Missing Authorization via rkt enter Command
CVSS 7.7
CVE-2019-10145 HIGH
rkt < 1.30.0 - Missing Authorization via rkt enter Command
CVSS 7.7
CVE-2019-10144 HIGH
rkt < 1.30.0 - Improper Privilege Management via rkt enter
CVSS 7.7
CVE-2019-10143 HIGH
Freeradius <3.0.19 - Privilege Escalation
CVSS 7.0
CVE-2018-25123 HIGH
Nagios XI <5.5.7 - Privilege Escalation
CVSS 7.8
CVE-2018-25078 HIGH
man-db <2.8.5 - Privilege Escalation
CVSS 7.8
CVE-2018-16888 MEDIUM
systemd <v237 - Privilege Escalation
CVSS 4.7
CVE-2018-5413 HIGH
Imperva SecureSphere <13.0-11.5 - Privilege Escalation
CVSS 8.8
CVE-2018-10853 HIGH
Linux kernel KVM <4.18 - Privilege Escalation
CVSS 7.0
CVE-2018-10872 MEDIUM
Red Hat Enterprise Linux 6.10 - Denial of Service via Stack Switch Exception Handling
CVSS 6.5
CVE-2018-10892 MEDIUM
Docker/Moby <current - Privilege Escalation
CVSS 5.3
CVE-2018-10856 MEDIUM
podman <0.6.1 - Privilege Escalation
CVSS 5.3
CVE-2018-1087 HIGH
kernel <4.16-4.17.3 - Use After Free
CVSS 8.0
CVE-2018-8853 HIGH
Philips Brilliance <2.6.2 - Privilege Escalation
CVSS 8.8
CVE-2017-7518 MEDIUM
Linux kernel <4.12 - Privilege Escalation
CVSS 5.5
Details
Vulnerabilities 341
Exploit Likelihood Medium