CVE-2019-5250

CVSS v3 Score
7.8
High
CVSS v2 Score
6.8
Medium

Vulnerability Description

Mate 20 Pro smartphones with versions earlier than 9.1.0.135(C00E133R3P1) have an improper authorization vulnerability. The software does not properly restrict certain operation of certain privilege, the attacker could trick the user into installing a malicious application before the user turns on student mode function. Successful exploit could allow the attacker to bypass the limit of student mode function.

CVSS:7.8(High)

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges ...

CVSS:7.8(High)

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a...

CVSS:7.8(High)

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can al...

CVSS:7.8(High)

cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

CVSS:7.8(High)

A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

CVSS:7.8(High)

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains...