CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,489)
page 191 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38438 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38437 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-38436 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33918 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33917 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33916 | Med | 0.36 | 5.5 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-41750 | Med | 0.36 | 5.5 | 0.00 | Aug 31, 2023 | Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 32047. | ||
| CVE-2023-21288 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-21234 | Med | 0.36 | 5.5 | 0.00 | Aug 14, 2023 | In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2023-33912 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33911 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33910 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33909 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33908 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33907 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33906 | Med | 0.36 | 5.5 | 0.00 | Aug 7, 2023 | In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | ||
| CVE-2023-33902 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-33901 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-33900 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-33899 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
Sensitive information disclosure due to missing authorization. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 32047.
- risk 0.36cvss 5.5epss 0.00
In visitUris of Notification.java, there is a possible way to reveal images across users due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.
- risk 0.36cvss 5.5epss 0.00
In launchConfirmationActivity of ChooseLockSettingsHelper.java, there is a possible way to enable developer options without the lockscreen PIN due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.36cvss 5.5epss 0.00
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges
- risk 0.36cvss 5.5epss 0.00
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In bluetooth service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.