Search Results (43 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2011-3350 1 Marmaro 1 Masqmail 2024-11-21 9.8 Critical
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-2921 1 Ktsuss Project 1 Ktsuss 2024-11-21 9.8 Critical
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified commands, which can result in command execution with root privileges.
CVE-2023-0657 1 Redhat 2 Build Keycloak, Red Hat Single Sign On 2024-11-18 3.4 Low
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.