Skip to main content

CWE archive

CWE-269 CVEs

Programmatic archive

3,175 CVEs tagged with CWE-269404 Critical, 1,935 High, 751 Medium, 84 Low, 1 Unrated.

CVE-2019-13702

Published Nov 25, 2019

Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform privilege escalation via a crafted executable.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2011-3349

Published Nov 19, 2019

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4954

Published Nov 19, 2019

cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-18368

Published Nov 15, 2019

Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attemp…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2011-2910

Published Nov 15, 2019

The AX.25 daemon (ax25d) in ax25-tools before 0.0.8-13 does not check the return value of a setuid call. The setuid call is responsible for dropping privileges but if the call fai…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14590

Published Nov 14, 2019

Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via…

CVSS 5.5 · Medium

CVE-2019-15332

Published Nov 14, 2019

The Lava Z61 Android device with a build fingerprint of LAVA/Z61_2GB/Z61_2GB:8.1.0/O11019/1533889281:user/release-keys contains a pre-installed app with a package name of com.andr…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-3651

Published Nov 13, 2019

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD prior to 4.8 allows remote authenticated attackers to gain access to ePO as an administrator via using…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-2193

Published Nov 13, 2019

In WelcomeActivity.java and related files, there is a possible permissions bypass due to a partially provisioned Device Policy Client. This could lead to local escalation of privi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1405

Published Nov 12, 2019

An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows COM object creation, aka 'Windows UPnP Service Elevation o…

CVSS 7.8 · High
evidence mentions
5
Buzz score
62.9
KEV listed

CVE-2019-1388

Published Nov 12, 2019

An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Pr…

CVSS 7.8 · High
evidence mentions
2
Buzz score
42.5
KEV listed

CVE-2019-18623

Published Nov 8, 2019

Escalation of privileges in EnergyCAP 7 through 7.5.6 allows an attacker to access data. If an unauthenticated user clicks on a link on the public dashboard, the resource opens in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-18365

Published Oct 31, 2019

In JetBrains TeamCity before 2019.1.4, reverse tabnabbing was possible on several pages.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-18931

Published Oct 29, 2019

An issue was discovered in the Tightrope Media Carousel digital signage product 7.0.4.104. Due to insecure default permissions on the C:\TRMS\Services directory, an attacker who h…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 2,776-2,800 of 3,175 CVEsPage 112 of 127