VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 198 of 475
  • CVE-2022-42782MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

  • CVE-2022-42766MedDec 6, 2022
    risk 0.36cvss 5.5epss 0.00

    In wlan driver, there is a possible missing permission check, This could lead to local information disclosure.

  • CVE-2022-39117MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2022-39115MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

  • CVE-2022-39114MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

  • CVE-2022-39113MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

  • CVE-2022-39112MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In Music service, there is a missing permission check. This could lead to local denial of service in Music service with no additional execution privileges needed.

  • CVE-2022-39103MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In Gallery service, there is a missing permission check. This could lead to local denial of service in Gallery service with no additional execution privileges needed.

  • CVE-2022-38697MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to access unexpected provider in contacts service with no additional execution privileges needed.

  • CVE-2022-38689MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2022-38688MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.

  • CVE-2022-38687MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In messaging service, there is a missing permission check. This could lead to local denial of service in messaging service with no additional execution privileges needed.

  • CVE-2022-38679MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In music service, there is a missing permission check. This could lead to local denial of service in music service with no additional execution privileges needed.

  • CVE-2022-38677MedOct 14, 2022
    risk 0.36cvss 5.5epss 0.00

    In cell service, there is a missing permission check. This could lead to local denial of service in cell service with no additional execution privileges needed.

  • CVE-2022-20341MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ConnectivityService, there is a possible bypass of network permissions due to a missing permission check. This could lead to local information disclosure of tethering interfaces with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-20326MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android…

  • CVE-2022-20323MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20322MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In PackageManager, there is a possible installed package disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…

  • CVE-2022-20312MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In WifiP2pManager, there is a possible toobtain WiFi P2P MAC address without user consent due to missing permission check. This could lead to local information disclosure without additional execution privileges needed. User interaction is not needed forexploitationProduct:…

  • CVE-2022-20303MedAug 12, 2022
    risk 0.36cvss 5.5epss 0.00

    In ContentService, there is a possible way to determine if an account is on the device without GET_ACCOUNTS permission due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for…