CWE-269
2,910 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,910)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing...Show more |
2Canonical Linux4Linux Kernel Ubuntu CoreUbuntu Linux+1 moreMay 6, 2026 May 2, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. |
1Microsoft 5Windows 10 1507 Windows 10 1511Windows 8.1+2 moreApr 21, 2026 Apr 12, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges...Show more |
3Canonical LinuxSuse3Linux Enterprise Real Time Extension Linux KernelUbuntu LinuxMay 6, 2026 Feb 8, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted...Show more |
5Canonical DebianEcryptfs+2 more6Debian Linux Ecryptfs UtilsFedora+3 moreMay 6, 2026 Jan 22, 2016 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid. |
3Canonical DebianSamba3Debian Linux SambaUbuntu LinuxMay 6, 2026 Dec 29, 2015 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 does not properly check for administrative privileges during cr...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
1Adobe 4Acrobat Acrobat DcAcrobat Reader+1 moreMay 6, 2026 Jul 15, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X al...Show more |
3Ibm RedhatSuse8Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Server Aus+5 moreMay 27, 2026 Jul 2, 2015 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to gain privileges via unknown vectors rela...Show more |
5Canonical DebianLinux+2 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 4.4 MEDIUM· v2 The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (g...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as...Show more |
4Canonical DebianLinux+1 more4Debian Linux LinuxLinux Kernel+1 moreMay 6, 2026 Mar 2, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than C...Show more |
Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting. |
6Canonical GoogleLinux+3 more6Android Enterprise Linux EusEvergreen+3 moreMay 6, 2026 Dec 17, 2014 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET inst...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxMay 6, 2026 Nov 14, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecified parameters related to rectangle handling. |
OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allows remote authenticated users to gain privileges that are assigned to a...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Aug 18, 2014 N/A· v4 N/A· v3 6.2 MEDIUM· v2 fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain p...Show more |
2Canonical Linux2Linux Kernel Ubuntu LinuxMay 6, 2026 Aug 18, 2014 N/A· v4 N/A· v3 7.2 HIGH· v2 The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind mount, which allows local users to bypass an intended read-only restrict...Show more |
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and wr...Show more |