← Back
CWE-648

66 CVEs • Abstraction: Base • Likelihood of Exploit: Low

Incorrect Use of Privileged APIs

The product does not conform to the API requirements for a function call that requires extra privileges. This could allow attackers to gain privileges by causing the function to be called incorrectly.

JSON object

Loading...

CVEs (66)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially cra...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
5Artifex
DebianFedoraproject+2 more
5Debian Linux
FedoraGhostscript+2 more
Jun 17, 2026
Sep 3, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafte...Show more
A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.Show less
1Modx
1Fred
Jun 17, 2026
Jul 24, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uplo...Show more
Fred MODX Revolution < 1.0.0-beta5 is affected by: Incorrect Access Control - CWE-648. The impact is: Remote Code Execution. The component is: assets/components/fred/web/elfinder/connector.php. The attack vector is: Uploading a PHP file or change data in the database. The fixed version is: https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246.Show less
6Artifex
CanonicalDebian+3 more
6Debian Linux
Enterprise LinuxFedora+3 more
Jun 17, 2026
May 16, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have acces...Show more
It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.Show less
5Artifex
DebianFedoraproject+2 more
12Ansible Tower
Debian LinuxEnterprise Linux+9 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the f...Show more
It was found that the forceput operator could be extracted from the DefineResource method in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.Show less
5Artifex
DebianFedoraproject+2 more
11Ansible Tower
Debian LinuxEnterprise Linux Desktop+8 more
Jun 17, 2026
Mar 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file syst...Show more
It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.Show less