Threats Tagged 'cwe-273'
View all threats tagged with 'cwe-273'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-273'
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability in Hugging Face Transformers (versions >= 4.49.0 and <= 5.8.1) allows remote Python files to be written to local disk without user consent when using GenerativePreTrainedModel.load_custom_generate(). The function fetches and caches a remote module file before performing the required trust_remote_code consent check, inverting the security model enforced by other code-loading paths (such as AutoConfig, AutoModel, and AutoTokenizer). As a result, attacker‑controlled Python code from custom_generate/generate.py is copied into the user’s ~/.cache/huggingface/modules directory even if the user declines the trust prompt. Although execution is correctly gated, the file write is not reversible and can persist across sessions. This can lead to persistent, unauthorized files on disk and stale cache collisions where cached attacker code may later be executed during trusted model loads. The issue stems from an unconditional file write in dynamic_module_utils.py prior to any trust verification. Join the discussion | CVE Database V5 | 09/01/2026, 13:40:05 UTC Added: 09/01/2026, 13:52:47 UTC |
0 CVE-2026-61897 is a local privilege escalation vulnerability in Ubuntu's accountsservice prior to version 23.13.9-8ubuntu7. The flaw arises because an Ubuntu-specific patch only partially drops privileges before launching language helper scripts, leaving the real user ID as root. This allows a shell spawned by the helper script to inherit root privileges and potentially regain full root access. The vulnerability has a high severity with a CVSS score of 7.8. Join the discussion | CVE Database V5 | 08/20/2026, 14:32:53 UTC Added: 08/20/2026, 14:38:09 UTC |
sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but can retain the parent process's supplementary groups because the privilege-drop sequence does not fully establish the target user's UID, primary GID, and supplementary groups. The child can therefore retain access to files or resources granted to privileged groups such as root, docker, disk, shadow, or sudo, violating the expected _uid privilege boundary. This issue is fixed in version 2.2.4. Join the discussion | CVE Database V5 | 08/18/2026, 17:37:40 UTC Added: 08/18/2026, 17:50:23 UTC |
xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6. Join the discussion | CVE Database V5 | 04/17/2026, 19:25:20 UTC Added: 04/17/2026, 19:53:07 UTC |
0 theshit is a command-line utility that automatically detects and fixes common mistakes in shell commands. Prior to version 0.2.0, improper privilege dropping allows local privilege escalation via command re-execution. This issue has been patched in version 0.2.0. Join the discussion | CVE Database V5 | 03/02/2026, 19:17:22 UTC Added: 03/02/2026, 19:33:21 UTC |
0 The vCenter Server contains a privilege escalation vulnerability. A malicious actor with network access to vCenter Server may trigger this vulnerability to escalate privileges to root by sending a specially crafted network packet. Join the discussion | CVE Database V5 | 09/17/2024, 17:13:13 UTC Added: 06/10/2025, 18:54:11 UTC |
Showing 1 to 6 of 6 results