CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,489)
page 188 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42646 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42644 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42643 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42642 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42641 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42640 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42639 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42638 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42637 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42636 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42635 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42634 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42633 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42632 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-42631 | Med | 0.36 | 5.5 | 0.00 | Nov 1, 2023 | In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed | ||
| CVE-2023-21382 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21340 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21329 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21321 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21294 | Med | 0.36 | 5.5 | 0.00 | Oct 30, 2023 | In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |
- risk 0.36cvss 5.5epss 0.00
In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed
- risk 0.36cvss 5.5epss 0.00
In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.