Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-01-24 CVE-2018-8654 Improper Privilege Management vulnerability in Microsoft Dynamics 365 8.0
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-269
6.5
2020-01-24 CVE-2012-6302 Improper Privilege Management vulnerability in Soapbox Project Soapbox 0.3.1
Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.
local
low complexity
soapbox-project CWE-269
7.8
2020-01-23 CVE-2012-4606 Improper Privilege Management vulnerability in Citrix Xenserver
Citrix XenServer 4.1, 6.0, 5.6 SP2, 5.6 Feature Pack 1, 5.6 Common Criteria, 5.6, 5.5, 5.0, and 5.0 Update 3 contains a Local Privilege Escalation Vulnerability which could allow local users with access to a guest operating system to gain elevated privileges.
local
low complexity
citrix CWE-269
7.8
2020-01-23 CVE-2019-17202 Improper Privilege Management vulnerability in Fasttracksoftware Admin BY Request
FastTrack Admin By Request 6.1.0.0 supports group policies that are supposed to allow only a select range of users to elevate to Administrator privilege at will.
local
low complexity
fasttracksoftware CWE-269
7.8
2020-01-23 CVE-2013-6773 Improper Privilege Management vulnerability in Splunk
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
local
low complexity
splunk CWE-269
7.8
2020-01-22 CVE-2018-16272 Improper Privilege Management vulnerability in Samsung products
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations.
network
low complexity
samsung CWE-269
critical
9.8
2020-01-22 CVE-2018-16271 Improper Privilege Management vulnerability in Samsung products
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations.
low complexity
samsung CWE-269
6.5
2020-01-22 CVE-2018-16270 Improper Privilege Management vulnerability in Samsung products
Samsung Galaxy Gear series before build RE2 includes the hcidump utility with no privilege or permission restriction.
network
low complexity
samsung CWE-269
7.5
2020-01-22 CVE-2018-16268 Improper Privilege Management vulnerability in Linux Tizen
The SoundServer/FocusServer system services in Tizen allow an unprivileged process to perform media-related system actions, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
4.3
2020-01-22 CVE-2018-16267 Improper Privilege Management vulnerability in Linux Tizen
The system-popup system service in Tizen allows an unprivileged process to perform popup-related system actions, due to improper D-Bus security policy configurations.
low complexity
linux CWE-269
8.1