Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2021-01-12 CVE-2021-1650 Improper Privilege Management vulnerability in Microsoft products
Windows Runtime C++ Template Library Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-01-12 CVE-2021-1649 Improper Privilege Management vulnerability in Microsoft products
Active Template Library Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-01-12 CVE-2021-1648 Improper Privilege Management vulnerability in Microsoft products
Microsoft splwow64 Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-01-12 CVE-2021-1646 Improper Privilege Management vulnerability in Microsoft products
Windows WLAN Service Elevation of Privilege Vulnerability
low complexity
microsoft CWE-269
6.6
2021-01-12 CVE-2021-1642 Improper Privilege Management vulnerability in Microsoft products
Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-269
7.8
2021-01-12 CVE-2020-35459 Improper Privilege Management vulnerability in multiple products
An issue was discovered in ClusterLabs crmsh through 4.2.1.
local
low complexity
clusterlabs debian CWE-269
7.2
2021-01-12 CVE-2020-26050 Improper Privilege Management vulnerability in Safervpn 5.0.3.3/5.0.4.15
SaferVPN for Windows Ver 5.0.3.3 through 5.0.4.15 could allow local privilege escalation from low privileged users to SYSTEM via a crafted openssl configuration file.
local
low complexity
safervpn CWE-269
7.2
2021-01-11 CVE-2021-0306 Improper Privilege Management vulnerability in Google Android
In addAllPermissions of PermissionManagerService.java, there is a possible permissions bypass when upgrading major Android versions which allows an app to gain the android.permission.ACTIVITY_RECOGNITION permission without user confirmation.
local
low complexity
google CWE-269
7.2
2021-01-11 CVE-2020-0471 Improper Privilege Management vulnerability in Google Android
In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation.
network
low complexity
google CWE-269
7.5
2021-01-11 CVE-2020-27059 Improper Privilege Management vulnerability in Google Android
In onAuthenticated of AuthenticationClient.java, there is a possible tapjacking attack when requesting the user's fingerprint due to an overlaid window.
local
google CWE-269
4.4