CVE-2024-0674

CVSS v3 Score
7.8
High

Vulnerability Description

Privilege escalation vulnerability in Lamassu Bitcoin ATM Douro machines, in its 7.1 version, which could allow a local user to acquire root permissions by modifying the updatescript.js, inserting special code inside the script and creating the done.txt file. This would cause the watchdog process to run as root and execute the payload stored in the updatescript.js.

CVSS:7.8(High)

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges ...

CVSS:7.8(High)

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, which allows local users to gain privileges or cause a...

CVSS:7.8(High)

lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can al...

CVSS:7.8(High)

cobbler has local privilege escalation via the use of insecure location for PYTHON_EGG_CACHE

CVSS:7.8(High)

A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.

CVSS:7.8(High)

An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains...