Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-7803 Improper Privilege Management vulnerability in multiple products
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored.
network
low complexity
redhat debian mozilla CWE-269
5.0
2018-06-11 CVE-2017-7782 Improper Privilege Management vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections.
network
low complexity
mozilla microsoft CWE-269
5.0
2018-06-11 CVE-2017-7767 Improper Privilege Management vulnerability in Mozilla Firefox and Firefox ESR
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access.
local
low complexity
mozilla microsoft CWE-269
2.1
2018-06-11 CVE-2017-5409 Improper Privilege Management vulnerability in Mozilla Firefox and Firefox ESR
The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access.
local
low complexity
mozilla microsoft CWE-269
3.6
2018-06-02 CVE-2018-11190 Improper Privilege Management vulnerability in Quest Disk Backup
Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 2 of 6).
network
low complexity
quest CWE-269
critical
9.0
2018-05-29 CVE-2018-1495 Improper Privilege Management vulnerability in IBM Flashsystem 840 Firmware and Flashsystem 900 Firmware
IBM FlashSystem V840 and V900 products could allow an authenticated attacker with specialized access to overwrite arbitrary files which could cause a denial of service.
network
low complexity
ibm CWE-269
5.5
2018-05-25 CVE-2018-1134 Improper Privilege Management vulnerability in Moodle
An issue was discovered in Moodle 3.x.
network
low complexity
moodle CWE-269
4.0
2018-05-24 CVE-2017-14187 Improper Privilege Management vulnerability in Fortinet Fortios
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.
local
low complexity
fortinet CWE-269
7.2
2018-05-22 CVE-2018-11323 Improper Privilege Management vulnerability in Joomla Joomla!
An issue was discovered in Joomla! Core before 3.8.8.
network
low complexity
joomla CWE-269
6.5
2018-05-18 CVE-2018-1000400 Improper Privilege Management vulnerability in Kubernetes Cri-O
Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have.
network
low complexity
kubernetes CWE-269
6.5