CWE-284
Improper Access Control
Description
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Hierarchy (View 1000)
Parents
none
Children
- CWE-1191
- CWE-1220
- CWE-1224
- CWE-1231
- CWE-1233
- CWE-1252
- CWE-1257
- CWE-1259
- CWE-1260
- CWE-1262
- CWE-1263
- CWE-1267
- CWE-1270
- CWE-1274
- CWE-1276
- CWE-1280
- CWE-1283
- CWE-1290
- CWE-1292
- CWE-1294
- CWE-1296
- CWE-1304
- CWE-1311
- CWE-1312
- CWE-1313
- CWE-1315
- CWE-1316
- CWE-1317
- CWE-1320
- CWE-1323
- CWE-1334
- CWE-269
- CWE-282
- CWE-285
- CWE-286
- CWE-287
- CWE-346
- CWE-749
- CWE-923
Related attack patterns (CAPEC)
CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578
CVEs mapped to this weakness (1,926)
page 62 of 97| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-27841 | Med | 0.36 | 5.5 | 0.00 | May 14, 2024 | The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory. | |
| CVE-2024-23267 | Med | 0.36 | 5.5 | 0.00 | Mar 8, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences. | |
| CVE-2024-23266 | Med | 0.36 | 5.5 | 0.00 | Mar 8, 2024 | The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system. | |
| CVE-2015-8697 | Med | 0.36 | 5.5 | 0.00 | Jun 27, 2017 | stalin 0.11-5 allows local users to write to arbitrary files. | |
| CVE-2015-3840 | Med | 0.36 | 5.5 | 0.00 | Jun 27, 2017 | The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission. | |
| CVE-2016-10335 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. | |
| CVE-2016-10334 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. | |
| CVE-2016-10333 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. | |
| CVE-2015-9024 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications. | |
| CVE-2015-9021 | Med | 0.36 | 5.5 | 0.00 | Jun 13, 2017 | In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled. | |
| CVE-2016-3107 | Med | 0.36 | 5.5 | 0.00 | Jun 8, 2017 | The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data. | |
| CVE-2016-6089 | Med | 0.36 | 5.5 | 0.00 | Jun 7, 2017 | IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926. | |
| CVE-2015-8275 | Med | 0.36 | 5.5 | 0.00 | Apr 10, 2017 | LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files. | |
| CVE-2013-7461 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2017 | A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions. | |
| CVE-2013-7460 | Med | 0.36 | 5.5 | 0.00 | Mar 14, 2017 | A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions. | |
| CVE-2016-9378 | Med | 0.36 | 5.5 | 0.00 | Feb 22, 2017 | Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery. | |
| CVE-2015-1976 | Med | 0.36 | 5.5 | 0.00 | Feb 8, 2017 | IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash. | |
| CVE-2016-3020 | Med | 0.36 | 5.5 | 0.00 | Feb 7, 2017 | IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content. | |
| CVE-2016-5026 | Med | 0.36 | 5.5 | 0.00 | Jan 30, 2017 | hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory. | |
| CVE-2016-1920 | Med | 0.36 | 5.5 | 0.00 | Jan 27, 2017 | Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service. |
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An app may be able to disclose kernel memory.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to bypass certain Privacy preferences.
- risk 0.36cvss 5.5epss 0.00
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. An app may be able to modify protected parts of the file system.
- risk 0.36cvss 5.5epss 0.00
stalin 0.11-5 allows local users to write to arbitrary files.
- risk 0.36cvss 5.5epss 0.00
The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS and MMS messages without the associated "WRITE_SMS" permission.
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
- risk 0.36cvss 5.5epss 0.00
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
- risk 0.36cvss 5.5epss 0.00
The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, which allows local users to gain access to sensitive data.
- risk 0.36cvss 5.5epss 0.00
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926.
- risk 0.36cvss 5.5epss 0.00
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files.
- risk 0.36cvss 5.5epss 0.00
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.
- risk 0.36cvss 5.5epss 0.00
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.
- risk 0.36cvss 5.5epss 0.00
Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM guest OS users to cause a denial of service (guest crash) by leveraging an incorrect choice for software interrupt delivery.
- risk 0.36cvss 5.5epss 0.00
IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to crash.
- risk 0.36cvss 5.5epss 0.00
IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content validation. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability to bypass validation and load a page with malicious content.
- risk 0.36cvss 5.5epss 0.00
hs.py in OnionShare before 0.9.1 allows local users to modify the hiddenservice by pre-creating the /tmp/onionshare directory.
- risk 0.36cvss 5.5epss 0.00
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.