Vulnerabilities > Improper Check for Dropped Privileges

DATE CVE VULNERABILITY TITLE RISK
2020-07-13 CVE-2020-14298 Improper Check for Dropped Privileges vulnerability in multiple products
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304.
local
low complexity
redhat docker CWE-273
8.8
2020-02-24 CVE-2019-20044 Improper Check for Dropped Privileges vulnerability in multiple products
In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option.
local
low complexity
zsh fedoraproject debian apple CWE-273
7.8
2020-01-07 CVE-2019-14879 Improper Check for Dropped Privileges vulnerability in Moodle
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9.
network
low complexity
moodle CWE-273
5.4
2019-11-28 CVE-2019-18276 Improper Check for Dropped Privileges vulnerability in multiple products
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11.
local
low complexity
gnu netapp oracle CWE-273
7.8
2019-11-19 CVE-2011-3350 Improper Check for Dropped Privileges vulnerability in Marmaro Masqmail 0.2.21/0.2.30
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
network
low complexity
marmaro CWE-273
critical
9.8
2019-11-19 CVE-2011-2921 Improper Check for Dropped Privileges vulnerability in Ktsuss Project Ktsuss 1.3/1.4
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
network
low complexity
ktsuss-project CWE-273
critical
9.8
2019-10-29 CVE-2012-1187 Improper Check for Dropped Privileges vulnerability in Bitlbee 3.0.4
Bitlbee does not drop extra group privileges correctly in unix.c
network
low complexity
bitlbee CWE-273
critical
9.8
2018-12-12 CVE-2018-8599 Improper Check for Dropped Privileges vulnerability in Microsoft products
An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability." This affects Microsoft Visual Studio, Windows Server 2019, Windows Server 2016, Windows 10, Windows 10 Servers.
local
low complexity
microsoft CWE-273
7.8
2018-10-30 CVE-2018-16466 Improper Check for Dropped Privileges vulnerability in Nextcloud Server
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
network
low complexity
nextcloud CWE-273
8.1
2017-03-22 CVE-2017-6972 Improper Check for Dropped Privileges vulnerability in multiple products
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-2017-6970 and CVE-2017-6971.
network
low complexity
alienvault nfsen CWE-273
critical
9.8