CWE-264
1,444 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-264page 9 of 29
- CVE-2013-3024HIGHCVSS 7.8EG 7.82018-05-24
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
- CVE-2014-1846HIGHCVSS 7.8EG 7.82018-04-27
Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.
- CVE-2014-1845HIGHCVSS 7.8EG 7.82018-04-27
An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.
- CVE-2013-3947HIGHCVSS 7.8EG 7.82018-04-24
Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IOCTL call.
- CVE-2016-10451HIGHCVSS 7.8EG 7.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/…
- CVE-2014-1226HIGHCVSS 7.8EG 7.82018-04-06
The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-6876.
- CVE-2013-6876HIGHCVSS 7.8EG 7.82018-04-06
The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and earlier. NOTE: this vulnerability was fix…
- CVE-2016-8482HIGHCVSS 7.8EG 7.82018-04-05
An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.
- CVE-2016-10232HIGHCVSS 7.8EG 7.82018-04-04
An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34386696. References: QC-CR#1024872.
- CVE-2016-10231HIGHCVSS 7.8EG 7.82018-04-04
An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.
- CVE-2015-9015HIGHCVSS 7.8EG 7.82018-04-04
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714120.
- CVE-2018-0176HIGHCVSS 7.8EG 7.82018-03-28
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the …
- CVE-2018-0169HIGHCVSS 7.8EG 7.82018-03-28
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the …
- CVE-2014-5443HIGHCVSS 7.8EG 7.82018-03-19
Seafile Server before 3.1.2 and Server Professional Edition before 3.1.0 allow local users to gain privileges via vectors related to ccnet handling user accounts.
- CVE-2015-7440HIGHCVSS 7.8EG 7.82018-03-15
IBM Rational Collaborative Lifecycle Management (CLM) 3.0.1 before 3.0.1.6 iFix7 Interim Fix 1, 4.0.x before 4.0.7 iFix10, 5.0.x before 5.0.2 iFix15, and 6.0.x before 6.0.1 iFix4; Rational Quality Manager (RQM) 3.0.x before 3.0.1.6 iFix7 I…
- CVE-2014-7272HIGHCVSS 7.8EG 7.82018-03-08
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitati…
- CVE-2015-7967HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service for Citrix Web Interface Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7966HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability th…
- CVE-2015-7965HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability th…
- CVE-2015-7964HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service for NPS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7963HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service for AD FS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7962HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service for Outlook Web App Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7961HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service Remote Web Workplace Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7598HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service TokenValidator Proxy Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7597HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service IIS Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2015-7596HIGHCVSS 7.8EG 7.82018-03-02
SafeNet Authentication Service End User Software Tools for Windows uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module.
- CVE-2014-10070HIGHCVSS 7.8EG 7.82018-02-27
zsh before 5.0.7 allows evaluation of the initial values of integer variables imported from the environment (instead of treating them as literal numbers). That could allow local privilege escalation, under some specific and atypical condit…
- CVE-2016-8742HIGHCVSS 7.8EG 7.82018-02-12
The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any …
- CVE-2015-1416HIGHCVSS 7.8EG 7.82018-02-05
Larry Wall's patch; patch in FreeBSD 10.2-RC1 before 10.2-RC1-p1, 10.2 before 10.2-BETA2-p2, and 10.1 before 10.1-RELEASE-p16; Bitrig; GNU patch before 2.2.5; and possibly other patch variants allow remote attackers to execute arbitrary sh…
- CVE-2018-0095HIGHCVSS 7.8EG 7.82018-01-18
A vulnerability in the administrative shell of Cisco AsyncOS on Cisco Email Security Appliance (ESA) and Content Security Management Appliance (SMA) could allow an authenticated, local attacker to escalate their privilege level and gain ro…
- CVE-2016-0327HIGHCVSS 7.8EG 7.82018-01-12
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local users to gain administrator privileges via unspecified vectors. IBM X-Force ID: 111643.
- CVE-2016-6804HIGHCVSS 7.8EG 7.82017-11-20
The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains a defective operation that allows execution of arbitrary code with elevated privileges. This requires that the locatio…
- CVE-2017-12261HIGHCVSS 7.8EG 7.82017-11-02
A vulnerability in the restricted shell of the Cisco Identity Services Engine (ISE) that is accessible via SSH could allow an authenticated, local attacker to run arbitrary CLI commands with elevated privileges. The vulnerability is due to…
- CVE-2015-5699HIGHCVSS 7.8EG 7.82017-10-22
The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell metacharacters in a cl-rctl command label.
- CVE-2015-5675HIGHCVSS 7.8EG 7.82017-10-10
The sys_amd64 IRET Handler in the kernel in FreeBSD 9.3 and 10.1 allows local users to gain privileges or cause a denial of service (kernel panic).
- CVE-2015-7359HIGHCVSS 7.8EG 7.82017-10-03
The (1) IsVolumeAccessibleByCurrentUser and (2) MountDevice methods in Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, do not check the impersonation level of impersonation tokens, which allows …
- CVE-2015-7358HIGHCVSS 7.8EG 7.82017-10-03
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when running on Windows, does not properly validate drive letter symbolic links, which allows local users to mount an encrypted…
- CVE-2015-3643HIGHCVSS 7.8EG 7.82017-09-28
usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging …
- CVE-2014-8156HIGHCVSS 7.8EG 7.82017-09-26
The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as packaged in Debian, the upstream cornucopia.git (fsoaudiod, fsodatad, fsodeviced, fsogsmd…
- CVE-2015-1590HIGHCVSS 7.8EG 7.82017-09-07
The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
- CVE-2015-1324HIGHCVSS 7.8EG 7.82017-08-25
Apport before 2.17.2-0ubuntu1.1 as packaged in Ubuntu 15.04, before 2.14.70ubuntu8.5 as packaged in Ubuntu 14.10, before 2.14.1-0ubuntu3.11 as packaged in Ubuntu 14.04 LTS, and before 2.0.1-0ubuntu17.9 as packaged in Ubuntu 12.04 LTS allow…
- CVE-2015-3617HIGHCVSS 7.8EG 7.82017-08-22
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.
- CVE-2016-5864HIGHCVSS 7.8EG 7.82017-08-16
In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, and if they are set to a large value, integer overflow is possible followed by buffer overfl…
- CVE-2016-5863HIGHCVSS 7.8EG 7.82017-08-16
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can lead to out-of-bounds accesses.
- CVE-2015-1795HIGHCVSS 7.8EG 7.82017-06-27
Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.
- CVE-2015-1591HIGHCVSS 7.8EG 7.82017-06-27
The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.
- CVE-2016-10341HIGHCVSS 7.8EG 7.82017-06-13
In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.
- CVE-2015-4596HIGHCVSS 7.8EG 7.82017-06-13
Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.
- CVE-2016-7818HIGHCVSS 7.8EG 7.82017-06-09
Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO …
- CVE-2017-6638HIGHCVSS 7.8EG 7.82017-06-08
A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and run an executable file with privileges equivalent to the Microsoft Windows SYS…
Map vulnerabilities like CWE-264 to your infrastructure
EchelonGraph correlates every CVE — across CWE-264 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →