Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-03-17 CVE-2017-20002 Improper Privilege Management vulnerability in Debian Linux and Shadow
The Debian shadow package before 1:4.5-1 for Shadow incorrectly lists pts/0 and pts/1 as physical terminals in /etc/securetty.
local
low complexity
debian CWE-269
7.8
2021-03-15 CVE-2020-4184 Improper Privilege Management vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 performs an operation at a privilege level that is higher than the minimum level required, which creates new weaknesses or amplifies the consequences of other weaknesses.
network
low complexity
ibm CWE-269
7.3
2021-03-02 CVE-2020-12528 Improper Privilege Management vulnerability in Mbconnectline Mbconnect24 and Mymbconnect24
An issue was discovered in MB connect line mymbCONNECT24 and mbCONNECT24 software in all versions through V2.6.2.
network
low complexity
mbconnectline CWE-269
7.7
2021-02-23 CVE-2021-26594 Improper Privilege Management vulnerability in Rangerstudio Directus
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end.
network
low complexity
rangerstudio CWE-269
8.8
2021-02-23 CVE-2021-25630 Improper Privilege Management vulnerability in Collaboraoffice Online
"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user.
local
low complexity
collaboraoffice CWE-269
7.8
2021-02-16 CVE-2021-20075 Improper Privilege Management vulnerability in Racom M!Dge Firmware 4.4.40.105
Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.
local
low complexity
racom CWE-269
7.8
2021-02-16 CVE-2020-35557 Improper Privilege Management vulnerability in multiple products
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.
network
low complexity
mbconnectline helmholz CWE-269
6.5
2021-02-15 CVE-2020-29031 Improper Privilege Management vulnerability in Secomea products
An Insecure Direct Object Reference vulnerability exists in the web UI of the GateManager which allows an authenticated attacker to reset the password of any user in its domain or any sub-domain, via escalation of privileges.
network
low complexity
secomea CWE-269
8.1
2021-02-10 CVE-2021-26936 Improper Privilege Management vulnerability in Replaysorcery Project Replaysorcery
The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalate privileges to root by specifying video output paths in privileged locations.
local
low complexity
replaysorcery-project CWE-269
7.8
2021-02-10 CVE-2021-0327 Improper Privilege Management vulnerability in Google Android
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities.
local
low complexity
google CWE-269
7.8