CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,487)
page 195 of 475| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-48378 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48377 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48376 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48375 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-48371 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. | ||
| CVE-2022-48370 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. | ||
| CVE-2022-48242 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges. | ||
| CVE-2022-47493 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47492 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-47490 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges. | ||
| CVE-2022-38685 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed. | ||
| CVE-2023-21091 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-20909 | Med | 0.36 | 5.5 | 0.00 | Apr 19, 2023 | In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2023-21029 | Med | 0.36 | 5.5 | 0.00 | Mar 24, 2023 | In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:… | ||
| CVE-2022-47484 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | ||
| CVE-2022-47483 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | ||
| CVE-2022-47482 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | ||
| CVE-2022-47481 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | ||
| CVE-2022-47480 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed. | ||
| CVE-2022-47479 | Med | 0.36 | 5.5 | 0.00 | Mar 10, 2023 | In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. |
- risk 0.36cvss 5.5epss 0.00
In engineermode service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In contacts service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In dialer service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In soter service, there is a possible missing permission check. This could lead to local denial of service with no additional execution privileges.
- risk 0.36cvss 5.5epss 0.00
In bluetooth service, there is a possible missing permission check. This could lead to local denial of service in bluetooth service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In canDisplayLocalUi of AppLocalePickerActivity.java, there is a possible way to change system app locales due to a missing permission check. This could lead to local denial of service across user boundaries with no additional execution privileges needed. User interaction is not…
- risk 0.36cvss 5.5epss 0.00
In multiple functions of RunningTasks.java, there is a possible privilege escalation due to a missing privilege check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.36cvss 5.5epss 0.00
In register of UidObserverController.java, there is a missing permission check. This could lead to local information disclosure of app usage with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID:…
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local denial of service in telephone service with no additional execution privileges needed.
- risk 0.36cvss 5.5epss 0.00
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.