Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-03-12 CVE-2020-7254 Improper Privilege Management vulnerability in Mcafee Advanced Threat Defense
Privilege Escalation vulnerability in the command line interface in McAfee Advanced Threat Defense (ATD) 4.x prior to 4.8.2 allows local users to execute arbitrary code via improper access controls on the sudo command.
local
low complexity
mcafee CWE-269
7.8
2020-03-10 CVE-2020-0063 Improper Privilege Management vulnerability in Google Android
In SurfaceFlinger, it is possible to override UI confirmation screen protected by the TEE.
local
google CWE-269
4.4
2020-03-10 CVE-2020-0052 Improper Privilege Management vulnerability in Google Android 10.0
In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass.
local
google CWE-269
1.9
2020-03-10 CVE-2020-0051 Improper Privilege Management vulnerability in Google Android 10.0
In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack.
local
google CWE-269
4.4
2020-03-10 CVE-2020-0036 Improper Privilege Management vulnerability in Google Android
In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass.
local
low complexity
google CWE-269
7.2
2020-03-10 CVE-2020-5253 Improper Privilege Management vulnerability in Nethack
NetHack before version 3.6.0 allowed malicious use of escaping of characters in the configuration file (usually .nethackrc) which could be exploited.
network
low complexity
nethack CWE-269
7.5
2020-03-10 CVE-2019-12429 Improper Privilege Management vulnerability in Gitlab
An issue was discovered in GitLab Community and Enterprise Edition 11.9 through 11.11.
network
low complexity
gitlab CWE-269
4.0
2020-03-07 CVE-2020-8635 Improper Privilege Management vulnerability in Wftpserver Wing FTP Server 6.2.3
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on installation directories and configuration files.
local
low complexity
wftpserver CWE-269
7.2
2020-03-06 CVE-2020-8113 Improper Privilege Management vulnerability in Gitlab
GitLab 10.7 and later through 12.7.2 has Incorrect Access Control.
network
low complexity
gitlab CWE-269
7.5
2020-03-06 CVE-2020-9756 Improper Privilege Management vulnerability in Patriotmemory Viper RGB Firmware 1.0/1.1
Patriot Viper RGB Driver 1.1 and prior exposes IOCTL and allows insufficient access control.
local
low complexity
patriotmemory CWE-269
4.6