Vulnerabilities > Permissions, Privileges, and Access Controls

DATE CVE VULNERABILITY TITLE RISK
2017-02-07 CVE-2016-10044 Permissions, Privileges, and Access Controls vulnerability in multiple products
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.
local
low complexity
linux google CWE-264
7.8
2017-02-06 CVE-2015-2794 Permissions, Privileges, and Access Controls vulnerability in Dotnetnuke
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
network
low complexity
dotnetnuke CWE-264
critical
9.8
2017-02-03 CVE-2016-9871 Permissions, Privileges, and Access Controls vulnerability in EMC Isilon Onefs
EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected system.
network
low complexity
emc CWE-264
7.2
2017-02-03 CVE-2016-8216 Permissions, Privileges, and Access Controls vulnerability in Dell EMC Data Domain OS
EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 family all versions prior to 5.6.2.0, EMC Data Domain OS (DD OS) 5.7 family all versions prior to 5.7.2.10 has a command injection vulnerability that could potentially be exploited by malicious users to compromise the affected system.
local
low complexity
dell CWE-264
6.7
2017-02-01 CVE-2016-6028 Permissions, Privileges, and Access Controls vulnerability in IBM Rational Collaborative Lifecycle Management
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.
network
low complexity
ibm CWE-264
4.3
2017-02-01 CVE-2016-3053 Permissions, Privileges, and Access Controls vulnerability in IBM AIX
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
local
low complexity
ibm CWE-264
7.8
2017-01-31 CVE-2016-9403 Permissions, Privileges, and Access Controls vulnerability in Mybb
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.
network
low complexity
mybb CWE-264
critical
9.8
2017-01-30 CVE-2016-6268 Permissions, Privileges, and Access Controls vulnerability in Trendmicro Smart Protection Server 2.5/2.6/3.0
Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan horse .war file in the Solr webapps directory.
local
low complexity
trendmicro CWE-264
7.8
2017-01-26 CVE-2016-10013 Permissions, Privileges, and Access Controls vulnerability in XEN
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
local
low complexity
xen CWE-264
7.8
2017-01-23 CVE-2016-9386 Permissions, Privileges, and Access Controls vulnerability in multiple products
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
local
low complexity
citrix xen CWE-264
7.8