Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-02-10 CVE-2021-26936 Improper Privilege Management vulnerability in Replaysorcery Project Replaysorcery
The replay-sorcery program in ReplaySorcery 0.4.0 through 0.5.0, when using the default setuid-root configuration, allows a local attacker to escalate privileges to root by specifying video output paths in privileged locations.
local
low complexity
replaysorcery-project CWE-269
7.8
2021-02-10 CVE-2021-0327 Improper Privilege Management vulnerability in Google Android
In getContentProviderImpl of ActivityManagerService.java, there is a possible permission bypass due to non-restored binder identities.
local
low complexity
google CWE-269
7.8
2021-01-28 CVE-2020-35517 Improper Privilege Management vulnerability in Qemu
A flaw was found in qemu.
local
low complexity
qemu CWE-269
8.2
2021-01-20 CVE-2020-6024 Improper Privilege Management vulnerability in Checkpoint Smartconsole
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.
local
low complexity
checkpoint CWE-269
7.8
2021-01-15 CVE-2021-0204 Improper Privilege Management vulnerability in Juniper Junos
A sensitive information disclosure vulnerability in delta-export configuration utility (dexp) of Juniper Networks Junos OS may allow a locally authenticated shell user the ability to create and read database files generated by the dexp utility, including password hashes of local users.
local
low complexity
juniper CWE-269
7.8
2021-01-14 CVE-2021-20618 Improper Privilege Management vulnerability in Acmailer and Acmailer DB
Privilege chaining vulnerability in acmailer ver.
network
low complexity
acmailer CWE-269
critical
9.8
2021-01-13 CVE-2021-1258 Improper Privilege Management vulnerability in multiple products
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device.
local
low complexity
cisco mcafee CWE-269
5.5
2021-01-13 CVE-2020-9141 Improper Privilege Management vulnerability in Huawei Emui and Magic UI
There is a improper privilege management vulnerability in some Huawei smartphone.
network
low complexity
huawei CWE-269
critical
9.1
2021-01-12 CVE-2021-1719 Improper Privilege Management vulnerability in Microsoft Sharepoint Enterprise Server and Sharepoint Server
Microsoft SharePoint Elevation of Privilege Vulnerability
network
low complexity
microsoft CWE-269
8.0
2021-01-12 CVE-2021-1712 Improper Privilege Management vulnerability in Microsoft products
Microsoft SharePoint Elevation of Privilege Vulnerability
network
low complexity
microsoft CWE-269
8.0