CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (8,103)
page 263 of 406| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-21816 | Med | 0.36 | 5.5 | 0.00 | Feb 7, 2022 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service. | ||
| CVE-2021-28507 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2022 | An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent. | ||
| CVE-2020-12488 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2021 | The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. | ||
| CVE-2021-25735 | Med | 0.36 | 6.5 | 0.06 | Sep 6, 2021 | A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the… | ||
| CVE-2021-25431 | Med | 0.36 | 5.5 | 0.00 | Jul 8, 2021 | Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer. | ||
| CVE-2021-25405 | Med | 0.36 | 5.5 | 0.00 | Jun 11, 2021 | An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files. | ||
| CVE-2021-25349 | Med | 0.36 | 5.5 | 0.00 | Mar 25, 2021 | Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent. | ||
| CVE-2020-24441 | Med | 0.36 | 5.5 | 0.02 | Nov 12, 2020 | Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in disclosure of sensitive information stored in databases used by the application. Exploitation requires a victim to… | ||
| CVE-2019-9530 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2019 | The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download any file found in the web root directory. | ||
| CVE-2019-9529 | Med | 0.36 | 5.5 | 0.00 | Oct 10, 2019 | The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device. | ||
| CVE-2016-10799 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2019 | cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). | ||
| CVE-2017-18416 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). | ||
| CVE-2017-18385 | Med | 0.36 | 5.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). | ||
| CVE-2019-6544 | Med | 0.36 | 5.6 | 0.01 | May 9, 2019 | GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is… | ||
| CVE-2016-8365 | Med | 0.36 | 5.5 | 0.00 | Apr 3, 2018 | OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and… | ||
| CVE-2015-8697 | Med | 0.36 | 5.5 | 0.00 | Jun 27, 2017 | stalin 0.11-5 allows local users to write to arbitrary files. | ||
| CVE-2015-3840 | Med | 0.36 | 5.5 | 0.00 | Jun 27, 2017 | The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission. | ||
| CVE-2016-10335 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. | ||
| CVE-2016-10334 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. | ||
| CVE-2016-10333 | Med | 0.36 | 5.5 | 0.01 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. |
- risk 0.36cvss 5.5epss 0.00
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.
- risk 0.36cvss 5.5epss 0.01
An issue has recently been discovered in Arista EOS where, under certain conditions, the service ACL configured for OpenConfig gNOI and OpenConfig RESTCONF might be bypassed, which results in the denied requests being forwarded to the agent.
- risk 0.36cvss 5.5epss 0.00
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- risk 0.36cvss 6.5epss 0.06
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the…
- risk 0.36cvss 5.5epss 0.00
Improper access control vulnerability in Cameralyzer prior to versions 3.2.1041 in 3.2.x, 3.3.1040 in 3.3.x, and 3.4.4210 in 3.4.x allows untrusted applications to access some functions of Cameralyzer.
- risk 0.36cvss 5.5epss 0.00
An improper access control vulnerability in ScreenOffActivity in Samsung Notes prior to version 4.2.04.27 allows untrusted applications to access local files.
- risk 0.36cvss 5.5epss 0.00
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
- risk 0.36cvss 5.5epss 0.02
Adobe Acrobat Reader for Android version 20.6.2 (and earlier) does not properly restrict access to directories created by the application. This could result in disclosure of sensitive information stored in databases used by the application. Exploitation requires a victim to…
- risk 0.36cvss 5.5epss 0.00
The web root directory of the Cobham EXPLORER 710, firmware version 1.07, has no access restrictions on downloading and reading all files. This could allow an unauthenticated, local attacker connected to the device to access and download any file found in the web root directory.
- risk 0.36cvss 5.5epss 0.00
The web application portal of the Cobham EXPLORER 710, firmware version 1.07, has no authentication by default. This could allow an unauthenticated, local attacker connected to the device to access the portal and to make any change to the device.
- risk 0.36cvss 5.5epss 0.00
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137).
- risk 0.36cvss 5.5epss 0.00
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
- risk 0.36cvss 5.5epss 0.00
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
- risk 0.36cvss 5.6epss 0.01
GE Communicator, all versions prior to 4.0.517, has a service running with system privileges that may allow an unprivileged user to perform certain administrative actions, which may allow the execution of scheduled scripts with system administrator privileges. This service is…
- risk 0.36cvss 5.5epss 0.00
OSIsoft PI System software (Applications using PI Asset Framework (AF) Client versions prior to PI AF Client 2016, Version 2.8.0; Applications using PI Software Development Kit (SDK) versions prior to PI SDK 2016, Version 1.4.6; PI Buffer Subsystem, versions prior to and…
- risk 0.36cvss 5.5epss 0.00
stalin 0.11-5 allows local users to write to arbitrary files.
- risk 0.36cvss 5.5epss 0.00
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
- risk 0.36cvss 5.5epss 0.01
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.