VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,489)

page 188 of 475
  • CVE-2023-42646MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In Ifaa service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42644MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In dm service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42643MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42642MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42641MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42640MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42639MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42638MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42637MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42636MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42635MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42634MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42633MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42632MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-42631MedNov 1, 2023
    risk 0.36cvss 5.5epss 0.00

    In validationtools, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges needed

  • CVE-2023-21382MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Content Resolver, there is a possible method to access metadata about existing content providers on the device due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2023-21340MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Telecomm, there is a possible way to get the call state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21329MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Activity Manager, there is a possible way to determine whether an app is installed due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21321MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Package Manager, there is a possible cross-user settings disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2023-21294MedOct 30, 2023
    risk 0.36cvss 5.5epss 0.00

    In Slice, there is a possible disclosure of installed packages due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.