CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,489)
page 194 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30918 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30913 | Med | 0.36 | 5.5 | 0.00 | Jul 12, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-21177 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is… | ||
| CVE-2023-21173 | Med | 0.36 | 5.5 | 0.00 | Jun 28, 2023 | In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for… | ||
| CVE-2023-21141 | Med | 0.36 | 5.5 | 0.00 | Jun 15, 2023 | In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2020-36702 | Med | 0.36 | 5.5 | 0.00 | Jun 7, 2023 | The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+… | ||
| CVE-2023-30915 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30914 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30866 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2023-30865 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | ||
| CVE-2022-48448 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48447 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48446 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48445 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48444 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48443 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48442 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48441 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48440 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48391 | Med | 0.36 | 5.5 | 0.00 | Jun 6, 2023 | In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. |
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In requestAppKeyboardShortcuts of WindowManagerService.java, there is a possible way to infer the app a user is interacting with due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is…
- risk 0.36cvss 5.5epss 0.00
In multiple methods of DataUsageList.java, there is a possible way to learn about admin user's network activities due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…
- risk 0.36cvss 5.5epss 0.00
In several functions of several files, there is a possible way to access developer mode traces due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
The Ultimate Addons for Gutenberg plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 1.14.7. This is due to missing capability checks on several AJAX actions. This makes it possible for authenticated attackers with subscriber+…
- risk 0.36cvss 5.5epss 0.00
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In email service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.