Vulnerabilities (CVE)

Filtered by CWE-273
Total 45 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-0278 3 Fedoraproject, Libuv Project, Nodejs 3 Fedora, Libuv, Node.js 2026-06-17 10.0 HIGH N/A
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
CVE-2012-1187 1 Bitlbee 1 Bitlbee 2026-06-16 7.5 HIGH 9.8 CRITICAL
Bitlbee does not drop extra group privileges correctly in unix.c
CVE-2011-3350 1 Marmaro 1 Masqmail 2026-06-16 7.5 HIGH 9.8 CRITICAL
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-2921 1 Ktsuss Project 1 Ktsuss 2026-06-16 10.0 HIGH 9.8 CRITICAL
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CVE-2006-2916 2 Kde, Linux 2 Arts, Linux Kernel 2026-06-16 6.0 MEDIUM 7.8 HIGH
artswrapper in aRts, when running setuid root on Linux 2.6.0 or later versions, does not check the return value of the setuid function call, which allows local users to gain root privileges by causing setuid to fail, which prevents artsd from dropping privileges.