CWE-264
1,444 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 10 of 29
- CVE-2016-8228HIGHCVSS 7.8EG 7.82017-06-04
In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.
- CVE-2016-1876HIGHCVSS 7.8EG 7.82017-05-23
The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.
- CVE-2015-8089HIGHCVSS 7.8EG 7.82017-05-23
The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows local users to read or write to arbitrary kernel memory locations and consequently cause a de…
- CVE-2017-6623HIGHCVSS 7.8EG 7.82017-05-18
A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to root. The vulnerabilit…
- CVE-2016-10238HIGHCVSS 7.8EG 7.82017-05-16
In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.
- CVE-2016-10277HIGHCVSS 7.8EG 7.82017-05-12
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local…
- CVE-2016-10276HIGHCVSS 7.8EG 7.82017-05-12
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-10275HIGHCVSS 7.8EG 7.82017-05-12
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-10274HIGHCVSS 7.8EG 7.82017-05-12
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a l…
- CVE-2015-9004HIGHCVSS 7.8EG 7.82017-05-02
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
- CVE-2015-8110HIGHCVSS 7.8EG 7.82017-04-24
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the…
- CVE-2016-10345HIGHCVSS 7.8EG 7.82017-04-18
In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers to gain the privileges of the passenger user.
- CVE-2016-6299HIGHCVSS 7.8EG 7.82017-04-14
The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
- CVE-2016-0727HIGHCVSS 7.8EG 7.82017-04-14
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3ubuntu5.3 on Ubuntu 16.04 LTS allows loc…
- CVE-2016-10123HIGHCVSS 7.8EG 7.82017-04-13
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.
- CVE-2016-10122HIGHCVSS 7.8EG 7.82017-04-13
Firejail does not properly clean environment variables, which allows local users to gain privileges.
- CVE-2016-10121HIGHCVSS 7.8EG 7.82017-04-13
Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.
- CVE-2016-10120HIGHCVSS 7.8EG 7.82017-04-13
Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.
- CVE-2016-10119HIGHCVSS 7.8EG 7.82017-04-13
Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.
- CVE-2016-10117HIGHCVSS 7.8EG 7.82017-04-13
Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.
- CVE-2016-8235HIGHCVSS 7.8EG 7.82017-04-10
Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with elevated privileges.
- CVE-2016-10323HIGHCVSS 7.8EG 7.82017-04-10
Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.
- CVE-2015-7260HIGHCVSS 7.8EG 7.82017-04-10
Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.
- CVE-2014-9922HIGHCVSS 7.8EG 7.82017-04-04
The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs layer, related to fs/ecryptfs/main.c and fs/overlayfs/super.c.
- CVE-2016-10225HIGHCVSS 7.8EG 7.82017-03-27
The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.
- CVE-2016-9775HIGHCVSS 7.8EG 7.82017-03-23
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+…
- CVE-2016-5857HIGHCVSS 7.8EG 7.82017-03-20
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.
- CVE-2016-8026HIGHCVSS 7.8EG 7.82017-03-14
Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.
- CVE-2016-8012HIGHCVSS 7.8EG 7.82017-03-14
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process…
- CVE-2016-8009HIGHCVSS 7.8EG 7.82017-03-14
Privilege escalation vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and 6.x versions allows attackers to cause DoS, unexpected behavior, or potentially unauthorized code execution via an unauthorized use of IOCTL call.
- CVE-2016-8479HIGHCVSS 7.8EG 7.82017-03-08
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local per…
- CVE-2016-7661HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related…
- CVE-2016-7660HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via uns…
- CVE-2016-7613HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attacker…
- CVE-2016-7583HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iCloud before 6.0.1 is affected. The issue involves the setup subsystem in the "iCloud" component. It allows local users to gain privileges via a crafted dynamic library in an unspecified …
- CVE-2016-4675HIGHCVSS 7.8EG 7.82017-02-20
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "libxpc" component. It allows attacker…
- CVE-2016-8972HIGHCVSS 7.8EG 7.82017-02-15
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
- CVE-2016-6079HIGHCVSS 7.8EG 7.82017-02-15
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. IBM APARs: IV88658, IV87981, IV88419, IV87640, IV88053.
- CVE-2016-1883HIGHCVSS 7.8EG 7.82017-02-15
The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vectors.
- CVE-2016-1881HIGHCVSS 7.8EG 7.82017-02-15
The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux compatibility layer setgroups system call.
- CVE-2016-1880HIGHCVSS 7.8EG 7.82017-02-15
The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists."
- CVE-2016-10089HIGHCVSS 7.8EG 7.82017-02-15
Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.
- CVE-2016-9353HIGHCVSS 7.8EG 7.82017-02-13
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a static key hard-coded in the program. Attackers could reverse the admin account password for u…
- CVE-2017-3813HIGHCVSS 7.8EG 7.82017-02-09
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated, local attacker to open Internet Explorer with the privileges of the SYSTEM user. The vul…
- CVE-2016-2779HIGHCVSS 7.8EG 7.82017-02-07
runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
- CVE-2016-10044HIGHCVSS 7.8EG 7.82017-02-07
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via …
- CVE-2016-3053HIGHCVSS 7.8EG 7.82017-02-01
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.
- CVE-2016-6268HIGHCVSS 7.8EG 7.82017-01-30
Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arbitrary code with root privileges via a Trojan horse .war file in the Solr webapps director…
- CVE-2016-10013HIGHCVSS 7.8EG 7.82017-01-26
Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.
- CVE-2016-9386HIGHCVSS 7.8EG 7.82017-01-23
The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain privileges via vectors involving "unexpected" base/limit values.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →