Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-01-13 CVE-2019-19728 Improper Privilege Management vulnerability in multiple products
SchedMD Slurm before 18.08.9 and 19.x before 19.05.5 executes srun --uid with incorrect privileges.
network
high complexity
schedmd opensuse debian CWE-269
7.5
2020-01-13 CVE-2012-4767 Improper Privilege Management vulnerability in Safend Data Protector Agent 3.4.5586.9772
An issue exists in Safend Data Protector Agent 3.4.5586.9772 in the securitylayer.log file in the logs.9972 directory, which could let a malicious user decrypt and potentially change the Safend security policies applied to the machine.
local
low complexity
safend CWE-269
6.1
2020-01-10 CVE-2013-6231 Improper Privilege Management vulnerability in ENG Spagobi 4.0
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
network
low complexity
eng CWE-269
8.8
2020-01-08 CVE-2019-19544 Improper Privilege Management vulnerability in Broadcom CA Automic Dollar Universe 5.3.3
CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges.
local
low complexity
broadcom CWE-269
7.8
2020-01-08 CVE-2016-6590 Improper Privilege Management vulnerability in Symantec products
A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite 8.0 prior to 8.0 HF4 and Suite 7.6 prior to 7.6 HF7, Symantec Ghost Solution Suite 3.1 prior to 3.1 MP4, Symantec Endpoint Virtualization 7.x prior to 7.6 HF7, and Symantec Encryption Desktop 10.x prior to 10.4.1, which could let a local malicious user execute arbitrary code.
local
low complexity
symantec CWE-269
7.8
2020-01-06 CVE-2019-19585 Improper Privilege Management vulnerability in Rconfig 3.9.3
An issue was discovered in rConfig 3.9.3.
local
low complexity
rconfig CWE-269
7.8
2019-12-31 CVE-2013-4161 Improper Privilege Management vulnerability in multiple products
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
7.8
2019-12-31 CVE-2019-7479 Improper Privilege Management vulnerability in Sonicwall Sonicos and Sonicosv
A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode.
network
low complexity
sonicwall CWE-269
7.2
2019-12-30 CVE-2013-2016 Improper Privilege Management vulnerability in multiple products
A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device.
local
low complexity
qemu debian novell CWE-269
7.8
2019-12-30 CVE-2019-20074 Improper Privilege Management vulnerability in Netis-Systems Dl4343 Firmware
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
network
low complexity
netis-systems CWE-269
8.8