Vulnerabilities > Permissions, Privileges, and Access Controls

DATE CVE VULNERABILITY TITLE RISK
2016-09-26 CVE-2016-6276 Permissions, Privileges, and Access Controls vulnerability in Citrix Linux Virtual Delivery Agent 1.3
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.
local
low complexity
citrix CWE-264
7.8
2016-09-26 CVE-2016-5406 Permissions, Privileges, and Access Controls vulnerability in Redhat Jboss Enterprise Application Platform
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.
network
low complexity
redhat CWE-264
8.8
2016-09-25 CVE-2016-4778 Permissions, Privileges, and Access Controls vulnerability in Apple products
The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
local
low complexity
apple CWE-264
7.8
2016-09-25 CVE-2016-4716 Permissions, Privileges, and Access Controls vulnerability in Apple mac OS X
diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors.
local
low complexity
apple CWE-264
7.8
2016-09-24 CVE-2016-6413 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 1.3(2F)
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.
local
low complexity
cisco CWE-264
7.8
2016-09-22 CVE-2016-6406 Permissions, Privileges, and Access Controls vulnerability in Cisco Email Security Appliance Firmware
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.
network
low complexity
cisco CWE-264
critical
9.8
2016-09-22 CVE-2016-6322 Permissions, Privileges, and Access Controls vulnerability in Redhat Quickstart Cloud Installer
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.
local
low complexity
redhat CWE-264
8.4
2016-09-21 CVE-2016-7093 Permissions, Privileges, and Access Controls vulnerability in XEN 4.5.3/4.6.3/4.7.0
Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by leveraging mishandling of instruction pointer truncation during emulation.
local
low complexity
xen CWE-264
8.2
2016-09-21 CVE-2016-7092 Permissions, Privileges, and Access Controls vulnerability in XEN
The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related to L3 recursive pagetables.
local
low complexity
xen CWE-264
8.2
2016-09-21 CVE-2016-4382 Permissions, Privileges, and Access Controls vulnerability in HP Performance Center
HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user validation failure" issue.
network
high complexity
hp CWE-264
8.3