Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2020-10-05 CVE-2020-8223 Improper Privilege Management vulnerability in multiple products
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
network
low complexity
nextcloud fedoraproject CWE-269
6.5
2020-09-24 CVE-2020-3396 Improper Privilege Management vulnerability in Cisco IOS XE 16.12.1
A vulnerability in the file system on the pluggable USB 3.0 Solid State Drive (SSD) for Cisco IOS XE Software could allow an authenticated, physical attacker to remove the USB 3.0 SSD and modify sensitive areas of the file system, including the namespace container protections.
low complexity
cisco CWE-269
7.2
2020-09-24 CVE-2015-4719 Improper Privilege Management vulnerability in Pexip Infinity 7.0/9
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
network
low complexity
pexip CWE-269
critical
9.8
2020-09-23 CVE-2020-25595 Improper Privilege Management vulnerability in multiple products
An issue was discovered in Xen through 4.14.x.
local
low complexity
xen fedoraproject debian opensuse CWE-269
7.8
2020-09-18 CVE-2020-8247 Improper Privilege Management vulnerability in Citrix products
Citrix ADC and Citrix Gateway 13.0 before 13.0-64.35, Citrix ADC and NetScaler Gateway 12.1 before 12.1-58.15, Citrix ADC 12.1-FIPS before 12.1-55.187, Citrix ADC and NetScaler Gateway 12.0, Citrix ADC and NetScaler Gateway 11.1 before 11.1-65.12, Citrix SD-WAN WANOP 11.2 before 11.2.1a, Citrix SD-WAN WANOP 11.1 before 11.1.2a, Citrix SD-WAN WANOP 11.0 before 11.0.3f, Citrix SD-WAN WANOP 10.2 before 10.2.7b are vulnerable to escalation of privileges on the management interface.
network
low complexity
citrix CWE-269
8.8
2020-09-17 CVE-2020-0403 Improper Privilege Management vulnerability in Google Android
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature.
local
low complexity
google CWE-269
6.7
2020-09-17 CVE-2020-24046 Improper Privilege Management vulnerability in Titanhq Spamtitan 7.07
A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07.
network
low complexity
titanhq CWE-269
7.2
2020-09-17 CVE-2020-0404 Improper Privilege Management vulnerability in multiple products
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause.
local
low complexity
google oracle CWE-269
5.5
2020-09-17 CVE-2020-0074 Improper Privilege Management vulnerability in Google Android
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains.
local
low complexity
google CWE-269
7.8
2020-09-11 CVE-2020-16875 Improper Privilege Management vulnerability in Microsoft Exchange Server 2016/2019
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user.
network
low complexity
microsoft CWE-269
8.4