CWE-273
39 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Check for Dropped Privileges
The product attempts to drop privileges but does not check or incorrectly checks to see if the drop succeeded.
CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Play With Docker Project 1Play With Docker Jun 17, 2026 Jun 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Play With Docker < 0.0.2 has an insecure CAP_SYS_ADMIN privileged mode causing the docker container to escape. |
A flaw was found in the QEMU virtio-fs shared file system daemon (virtiofsd) implementation. This flaw is strictly related to CVE-2018-13405. A local guest user can create files in the directories shared by virtio-fs wit...Show more |
Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have no permission on. This metadata included the dataset name, columns and metrics. |
Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with low privilege permissions, may take advantage of the way CAP_SYS_NICE is currently implemented and...Show more |
In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can be retrieved with authenticated users with permission to the key. Authenticated users may use them...Show more |
2Debian Snmptt2Debian Linux SnmpttJun 17, 2026 Aug 16, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec. |
2Docker Redhat2Docker Enterprise Linux ServerJun 17, 2026 Jul 13, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc th...Show more |
2Docker Redhat3Docker Enterprise Linux ServerOpenshift Container PlatformJun 17, 2026 Jul 13, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304....Show more |
4Apple DebianFedoraproject+1 more8Debian Linux FedoraIpados+5 moreJun 17, 2026 Feb 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH...Show more |
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable)...Show more |
3Gnu NetappOracle5Bash Communications Cloud Native Core PolicyHci Management Node+2 moreJun 17, 2026 Nov 28, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID...Show more |
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping. |
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges. |
Bitlbee does not drop extra group privileges correctly in unix.c |
1Microsoft 5Visual Studio Visual Studio 2017Windows 10+2 moreJun 17, 2026 Dec 12, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly impersonates certain file operations, aka "Diagnostics Hub Standard Collector Service Elevation of Privilege V...Show more |
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. |
2Alienvault Nfsen3Nfsen OssimUnified Security ManagementMay 13, 2026 Mar 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execute the NfSen Perl code as root, aka AlienVault ID ENG-104945, a different vulnerability than CVE-201...Show more |
3Fedoraproject Libuv ProjectNodejs3Fedora LibuvNode.jsMay 6, 2026 May 18, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. |
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, whi...Show more |