CWE-264
1,444 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 2 of 29
- CVE-2016-10233CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.
- CVE-2016-10230CRITICALCVSS 9.8EG 9.82018-04-04
A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.
- CVE-2015-9014CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.
- CVE-2015-9013CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393251.
- CVE-2015-9012CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384691.
- CVE-2015-9011CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714882.
- CVE-2015-9010CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393101.
- CVE-2015-9009CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393600.
- CVE-2015-9008CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384689.
- CVE-2014-9959CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36383694.
- CVE-2014-9958CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384774.
- CVE-2014-9957CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.
- CVE-2014-9956CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.
- CVE-2014-9955CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384686.
- CVE-2014-9954CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.
- CVE-2014-9953CRITICALCVSS 9.8EG 9.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.
- CVE-2018-5472CRITICALCVSS 9.8EG 9.82018-03-26
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary c…
- CVE-2018-5468CRITICALCVSS 9.8EG 9.82018-03-26
Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unauthorized access and in some cases escalate their level of privilege or execute arbitrary code
- CVE-2018-7500CRITICALCVSS 9.8EG 9.82018-03-14
A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.
- CVE-2018-0130CRITICALCVSS 9.8EG 9.82018-02-22
A vulnerability in the use of JSON web tokens by the web-based service portal of Cisco Elastic Services Controller Software could allow an unauthenticated, remote attacker to gain administrative access to an affected system. The vulnerabil…
- CVE-2014-7862CRITICALCVSS 9.8EG 9.82018-01-04
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.
- CVE-2014-0073CRITICALCVSS 9.8EG 9.82017-10-30
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callb…
- CVE-2015-4650CRITICALCVSS 9.8EG 9.82017-10-16
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote attackers to gain shell access and execute arbitrary code with root privileges via unspecified vectors.
- CVE-2015-4683CRITICALCVSS 9.8EG 9.82017-09-19
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.
- CVE-2015-4629CRITICALCVSS 9.8EG 9.82017-09-07
Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perform other unspecified actions.
- CVE-2014-8428CRITICALCVSS 9.8EG 9.82017-08-28
Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.
- CVE-2015-5244CRITICALCVSS 9.8EG 9.82017-08-07
The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.
- CVE-2015-2560CRITICALCVSS 9.8EG 9.82017-08-02
Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModifyUser operation to servlets/DCOperationsServlet.
- CVE-2017-6713CRITICALCVSS 9.8EG 9.82017-07-06
A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access to the affected system. The vulnerability is due to static, default credentials for the Ci…
- CVE-2017-6640CRITICALCVSS 9.8EG 9.82017-06-08
A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administrative console of a DCNM server by using an account that has a default, static password. Th…
- CVE-2017-6622CRITICALCVSS 9.8EG 9.82017-05-18
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missin…
- CVE-2016-10372CRITICALCVSS 9.8EG 9.82017-05-16
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which d…
- CVE-2016-3067CRITICALCVSS 9.8EG 9.82017-04-21
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.
- CVE-2016-6727CRITICALCVSS 9.8EG 9.82017-04-17
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.
- CVE-2014-7921CRITICALCVSS 9.8EG 9.82017-04-13
mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.
- CVE-2014-7920CRITICALCVSS 9.8EG 9.82017-04-13
mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.
- CVE-2015-8965CRITICALCVSS 9.8EG 9.82017-04-06
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFa…
- CVE-2016-10152CRITICALCVSS 9.8EG 9.82017-03-28
The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file fails, which allows remote attackers to gain root privileges by poisoning the DNS cache.
- CVE-2014-7279CRITICALCVSS 9.8EG 9.82017-03-23
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.
- CVE-2015-8954CRITICALCVSS 9.8EG 9.82017-03-20
The MemcmpLowercase function in Suricata before 2.0.6 improperly excludes the first byte from comparisons, which might allow remote attackers to bypass intrusion-prevention functionality via a crafted HTTP request.
- CVE-2014-8708CRITICALCVSS 9.8EG 9.82017-03-17
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
- CVE-2017-3831CRITICALCVSS 9.8EG 9.82017-03-15
A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated, remote attacker to bypass authentication. The attacker could be granted full administrator privileges. The vulnerabili…
- CVE-2016-7955CRITICALCVSS 9.8EG 9.82017-03-15
The logcheck function in session.inc in AlienVault OSSIM before 5.3.1, when an action has been created, and USM before 5.3.1 allows remote attackers to bypass authentication and consequently obtain sensitive information, modify the applica…
- CVE-2014-9921CRITICALCVSS 9.8EG 9.82017-03-14
Information disclosure vulnerability in McAfee (now Intel Security) Cloud Analysis and Deconstructive Services (CADS) 1.0.0.3x, 1.0.0.4d and earlier allows remote unauthenticated users to view, add, and remove users via a configuration err…
- CVE-2016-9366CRITICALCVSS 9.8EG 9.82017-02-13
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2.8, NPort 5400 Series versions prior to 3.11, NPort 5600 Series versions prior to 3.7, NPo…
- CVE-2015-8768CRITICALCVSS 9.8EG 9.82017-02-13
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated …
- CVE-2015-2794CRITICALCVSS 9.8EG 9.82017-02-06
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
- CVE-2016-10150CRITICALCVSS 9.8EG 9.82017-02-06
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to cause a denial of service (host OS crash) or possibly gain privileges via crafted ioctl c…
- CVE-2016-9403CRITICALCVSS 9.8EG 9.82017-01-31
newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leveraging a missing permission check.
- CVE-2015-3188CRITICALCVSS 9.8EG 9.82017-01-13
The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →