Vulnerabilities > Improper Privilege Management

DATE CVE VULNERABILITY TITLE RISK
2019-09-06 CVE-2019-9443 Improper Privilege Management vulnerability in Google Android
In the Android kernel in the vl53L0 driver there is a possible out of bounds write due to a permissions bypass.
local
low complexity
google CWE-269
6.7
2019-09-05 CVE-2019-1939 Improper Privilege Management vulnerability in Cisco Webex Teams 3.0.4533
A vulnerability in the Cisco Webex Teams client for Windows could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system.
network
low complexity
cisco CWE-269
8.8
2019-08-29 CVE-2019-4536 Improper Privilege Management vulnerability in IBM I 7.4
IBM i 7.4 users who have done a Restore User Profile (RSTUSRPRF) on a system which has been configured with Db2 Mirror for i might have user profiles with elevated privileges caused by incorrect processing during a restore of multiple user profiles.
local
high complexity
ibm CWE-269
6.3
2019-08-28 CVE-2019-15720 Improper Privilege Management vulnerability in Cloudberrylab Backup 6.1.2.34
CloudBerry Backup v6.1.2.34 allows local privilege escalation via a Pre or Post backup action.
local
low complexity
cloudberrylab CWE-269
7.8
2019-08-26 CVE-2019-4448 Improper Privilege Management vulnerability in IBM DB2 High Performance Unload Load 6.1/6.1.0.1/6.1.0.2
IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum and db2hpum_debug binaries are setuid root and have built-in options that allow an low privileged user the ability to load arbitrary db2 libraries from a privileged context.
local
low complexity
ibm CWE-269
7.8
2019-08-21 CVE-2019-11551 Improper Privilege Management vulnerability in Code42 products
In Code42 Enterprise and Crashplan for Small Business through Client version 6.9.1, an attacker can craft a restore request to restore a file through the Code42 app to a location they do not have privileges to write.
local
low complexity
code42 CWE-269
5.5
2019-08-20 CVE-2019-11521 Improper Privilege Management vulnerability in Open-Xchange Appsuite 7.10.1
OX App Suite 7.10.1 allows Content Spoofing.
network
low complexity
open-xchange CWE-269
8.1
2019-08-20 CVE-2019-12889 Improper Privilege Management vulnerability in Sailpoint Desktop Password Reset 7.2
An unauthenticated privilege escalation exists in SailPoint Desktop Password Reset 7.2.
local
high complexity
sailpoint CWE-269
7.0
2019-08-12 CVE-2019-12618 Improper Privilege Management vulnerability in Hashicorp Nomad 0.9.0/0.9.1
HashiCorp Nomad 0.9.0 through 0.9.1 has Incorrect Access Control via the exec driver.
network
low complexity
hashicorp CWE-269
critical
9.8
2019-07-24 CVE-2019-1010178 Improper Privilege Management vulnerability in Modx Fred 1.0.0
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648.
network
low complexity
modx CWE-269
critical
9.8