VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 197 of 475
  • CVE-2022-47326MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

  • CVE-2022-47325MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

  • CVE-2022-47324MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.

  • CVE-2022-44421MedFeb 12, 2023
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check. This could lead to local In wlan driver, information disclosure.

  • CVE-2022-44439MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44438MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44437MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44436MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44435MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44434MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44424MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44423MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-44422MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In music service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-39104MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a missing permission check. This could lead to local denial of service in Contacts service with no additional execution privileges needed.

  • CVE-2022-38684MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-38683MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-38682MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-38678MedJan 4, 2023
    risk 0.36cvss 5.5epss 0.00

    In contacts service, there is a missing permission check. This could lead to local denial of service in contacts service with no additional execution privileges needed.

  • CVE-2022-20511MedDec 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In getNearbyAppStreamingPolicy of DevicePolicyManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20510MedDec 16, 2022
    risk 0.36cvss 5.5epss 0.00

    In getNearbyNotificationStreamingPolicy of DevicePolicyManagerService.java, there is a possible way to learn about the notification streaming policy of other users due to a permissions bypass. This could lead to local information disclosure with no additional execution…