CWE-269
2,910 CVEs • Abstraction: Class • Likelihood of Exploit: Medium
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CVEs (2,910)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian LinuxOpensuse+2 more6Debian Linux Enterprise Linux Server AusLinux Enterprise Desktop+3 moreMay 6, 2026 Jul 19, 2014 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure differences between an l2tp socket and an inet socket. |
OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allows remote authenticated users to gain privileges by leveraging a (1) tr...Show more |
sapi/fpm/fpm/fpm_unix.c in the FastCGI Process Manager (FPM) in PHP before 5.4.28 and 5.5.x before 5.5.12 uses 0666 permissions for the UNIX socket, which allows local users to gain privileges via a crafted FastCGI clien...Show more |
7Canonical DebianFedoraproject+4 more15Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+12 moreMay 6, 2026 Apr 30, 2014 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execu...Show more |
4Canonical FedoraprojectMozilla+1 more5Fedora FirefoxOpensuse+2 moreMay 6, 2026 Apr 30, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger,...Show more |
maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a...Show more |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. |
6Canonical DebianMozilla+3 more16Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+13 moreMay 6, 2026 Mar 19, 2014 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privile...Show more |
2Mozilla Suse6Firefox SeamonkeySuse Linux Enterprise Desktop+3 moreMay 6, 2026 Mar 19, 2014 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update. |
3Canonical OpenstackRedhat3Keystone OpenstackUbuntu LinuxApr 29, 2026 Dec 14, 2013 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by ge...Show more |
4Adobe OpensuseRedhat+1 more8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreApr 21, 2026 Feb 27, 2013 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x before 11.2.202.273 on Linux, does not properly restrict privileges, whic...Show more |
The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrictions and write to arbitrary files by leveraging access to a renderer pr...Show more |
1Mozilla 4Firefox SeamonkeyThunderbird+1 moreApr 29, 2026 Oct 10, 2012 N/A· v4 N/A· v3 9.3 HIGH· v2 The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 does not properly inte...Show more |
Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.xS before 3.5.1S, and 3.1.xSG and 3.2.xSG before 3.2.2SG, when AAA autho...Show more |
The WebUI privilege implementation in Google Chrome before 17.0.963.83 does not properly perform isolation, which allows remote attackers to bypass intended access restrictions via unspecified vectors. |
Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, which allows remote attackers to have an unspecified impact via a craft...Show more |
5Debian FedoraprojectMit+2 more7Debian Linux FedoraKrb5 Appl+4 moreApr 29, 2026 Jul 11, 2011 N/A· v4 N/A· v3 6.5 MEDIUM· v2 ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group acc...Show more |
4Fedoraproject LinuxOpensuse+1 more7Fedora Linux Enterprise DesktopLinux Enterprise Real Time Extension+4 moreApr 29, 2026 Dec 30, 2010 N/A· v4 N/A· v3 6.2 MEDIUM· v2 The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel...Show more |
3Linux OpensuseSuse3Linux Enterprise Real Time Extension Linux KernelOpensuseApr 29, 2026 Dec 22, 2010 N/A· v4 N/A· v3 6.9 MEDIUM· v2 The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables,...Show more |
3Canonical LinuxSuse3Linux Enterprise Real Time Extension Linux KernelUbuntu LinuxApr 29, 2026 Sep 22, 2010 N/A· v4 N/A· v3 7.2 HIGH· v2 The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not zero extend the %eax register after the 32-bit entry path to ptrace is...Show more |