VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 195 of 475
  • CVE-2022-48378MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48377MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48376MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48375MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-48371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.

  • CVE-2022-48370MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.

  • CVE-2022-48242MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.

  • CVE-2022-47493MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-47492MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-47490MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.

  • CVE-2022-38685MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.

  • CVE-2023-21091MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not…

  • CVE-2023-20909MedApr 19, 2023
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2023-21029MedMar 24, 2023
    risk 0.36cvss 5.5epss 0.00

    In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…

  • CVE-2022-47484MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

  • CVE-2022-47483MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

  • CVE-2022-47482MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

  • CVE-2022-47481MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

  • CVE-2022-47480MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.

  • CVE-2022-47479MedMar 10, 2023
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.