Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-04-29 CVE-2020-11446 Improper Privilege Management vulnerability in Eset products
ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege escalation.
local
low complexity
eset CWE-269
4.6
2020-04-29 CVE-2019-20781 Improper Privilege Management vulnerability in LG Bridge
An issue was discovered in LG Bridge before April 2019 on Windows.
local
lg CWE-269
4.4
2020-04-29 CVE-2019-16653 Improper Privilege Management vulnerability in Geniusbytes Genius Server 3.2.2
An application plugin in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to gain admin privileges.
network
low complexity
geniusbytes CWE-269
6.5
2020-04-28 CVE-2019-15876 Improper Privilege Management vulnerability in Freebsd 11.3/12.1
In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.
local
low complexity
freebsd CWE-269
2.1
2020-04-28 CVE-2018-21226 Improper Privilege Management vulnerability in Netgear products
Certain NETGEAR devices are affected by authentication bypass.
low complexity
netgear CWE-269
5.8
2020-04-28 CVE-2019-15790 Improper Privilege Management vulnerability in multiple products
Apport reads and writes information on a crashed process to /proc/pid with elevated privileges.
local
low complexity
apport-project canonical CWE-269
3.3
2020-04-27 CVE-2020-9072 Improper Privilege Management vulnerability in Huawei OSD Firmware
Huawei OSD product with versions earlier than OSD_uwp_9.0.32.0 have a local privilege escalation vulnerability.
local
low complexity
huawei CWE-269
4.6
2020-04-27 CVE-2020-7135 Improper Privilege Management vulnerability in HP Service Pack for Proliant
A potential security vulnerability has been identified in the disk drive firmware installers named Supplemental Update / Online ROM Flash Component on HPE servers running Linux.
local
low complexity
hp CWE-269
4.6
2020-04-27 CVE-2020-1845 Improper Privilege Management vulnerability in Huawei Pcmanager
Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability.
local
low complexity
huawei CWE-269
4.6
2020-04-27 CVE-2020-12242 Improper Privilege Management vulnerability in Valvesoftware Source
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
local
low complexity
valvesoftware CWE-269
7.2