Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-04-22 CVE-2021-0255 Improper Privilege Management vulnerability in Juniper Junos
A local privilege escalation vulnerability in ethtraceroute of Juniper Networks Junos OS may allow a locally authenticated user with shell access to escalate privileges and write to the local filesystem as root.
local
low complexity
juniper CWE-269
7.8
2021-04-21 CVE-2021-31523 Improper Privilege Management vulnerability in Xscreensaver Project Xscreensaver 5.42+Dfsg11
The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/sonar file, which allows local users to gain privileges because this is arguably incompatible with the design of the Mesa 3D Graphics library dependency.
local
low complexity
xscreensaver-project CWE-269
7.8
2021-04-19 CVE-2021-20208 Improper Privilege Management vulnerability in multiple products
A flaw was found in cifs-utils in versions before 6.13.
local
high complexity
samba redhat fedoraproject CWE-269
6.1
2021-04-19 CVE-2021-21981 Improper Privilege Management vulnerability in VMWare Nsx-T Data Center 3.1.1
VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role assignment.
local
low complexity
vmware CWE-269
7.8
2021-04-15 CVE-2021-30479 Improper Privilege Management vulnerability in Zulip Server
An issue was discovered in Zulip Server before 3.4.
network
low complexity
zulip CWE-269
5.3
2021-04-15 CVE-2021-30478 Improper Privilege Management vulnerability in Zulip Server
An issue was discovered in Zulip Server before 3.4.
network
low complexity
zulip CWE-269
4.3
2021-04-12 CVE-2020-15390 Improper Privilege Management vulnerability in Pega Platform 8.4.0.237
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
network
low complexity
pega CWE-269
critical
9.8
2021-04-09 CVE-2021-25377 Improper Privilege Management vulnerability in Samsung Experience Service
Intent redirection in Samsung Experience Service versions 10.8.0.4 in Android P(9.0) below, and 12.2.0.5 in Android Q(10.0) above allows attacker to execute privileged action.
local
low complexity
samsung CWE-269
7.8
2021-04-09 CVE-2021-25363 Improper Privilege Management vulnerability in Google Android
An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to access running processesdelete some local files.
local
low complexity
google CWE-269
6.1
2021-04-09 CVE-2021-25362 Improper Privilege Management vulnerability in Google Android 10.0/8.1/9.0
An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to delete certain local files.
local
low complexity
google CWE-269
6.1