CWE-269

Medium likelihood

Improper Privilege Management

Parent: CWE-284 - Improper Access Control

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

2,838 vulnerabilities with CWE-269
CVE-2015-9390 MEDIUM
admin_management_xtended < 2.4.0.1 - Privilege Escalation via wp_ajax Mishandling
CVSS 4.3
CVE-2015-9267 MEDIUM
Nullsoft Scriptable Install System < 2.49 - Unprivileged File Overwrite via Temporary Folder
CVSS 5.5
CVE-2015-8539 HIGH
Linux kernel <4.4 - Privilege Escalation
CVSS 7.8
CVE-2015-8467 HIGH
Samba 4.x <4.1.22, 4.2.x <4.2.7, 4.3.x <4.3.3 - Privilege Escalation
CVSS 7.5
CVE-2015-5106
Adobe Acrobat and Reader Privilege Escalation (10.x < 10.1.15, 11.x < 11.0.12, DC < 2015.006.30060/2015.008.20082)
CVE-2015-5090
Adobe Acrobat and Reader Privilege Escalation (10.x < 10.1.15, 11.x < 11.0.12, DC < 2015.006.30060/2015.008.20082)
CVE-2015-4446
Adobe Acrobat < 10.1.15 - Improper Privilege Management
CVE-2015-0192 CRITICAL
IBM Java 5.0.0.0-5.0.16.9 - Remote Privilege Escalation in Java Virtual Machine
CVSS 9.8
CVE-2015-0239
Linux Kernel < 3.18.5 - Privilege Escalation via SYSENTER Emulation
CVE-2014-125001 HIGH
Cardo Systems Scala Rider Q3 Firmware - Unauthenticated Remote Code Execution via Cardo-Updater API
CVSS 8.1
CVE-2014-4170 CRITICAL
ArticleFR 11.06.2014 - Privilege Escalation
CVSS 9.8
CVE-2014-6448 HIGH
Juniper Junos OS <13.2R5-13.3R3 - Privilege Escalation
CVSS 7.8
CVE-2014-9644
Linux kernel <3.18.5 - Local Privilege Escalation
CVE-2014-9193
Innominate mGuard <7.6.6, <8.1.4 - Privilege Escalation
CVE-2014-9322 HIGH
Linux kernel <3.17.5 - Privilege Escalation
CVSS 7.8
CVE-2014-3689
QEMU < 2.1.3 - Privilege Escalation via vmware-vga Rectangle Handling
CVE-2014-0204
OpenStack Identity <2014.1.1 - Privilege Escalation
CVE-2014-5207
Linux Kernel < 3.16.1 - Privilege Escalation via Bind Mount Remount
CVE-2014-5206
Linux Kernel < 3.16.1 - Privilege Escalation via Remount of Bind Mount
CVE-2014-3534
Linux Kernel < 3.15.8 - Privilege Escalation via PTRACE_POKEUSR_AREA Request
CVE-2014-4943
Linux Kernel <3.15.6 - Privilege Escalation
CVE-2014-3476
OpenStack Keystone Privilege Escalation via Chained Delegation
CVE-2014-0185
PHP <5.4.28, <5.5.12 - Privilege Escalation
CVE-2014-1529 HIGH
Firefox < 29.0 - Remote Code Execution via Web Notification API
CVSS 8.8
CVE-2014-1526
Firefox < 29.0 and SeaMonkey < 2.26 - Privilege Escalation via XrayWrapper Debugger Bypass
Details
Vulnerabilities 2,838
Exploit Likelihood Medium