VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,487)

page 203 of 475
  • CVE-2020-0106MedMay 14, 2020
    risk 0.36cvss 5.5epss 0.00

    In getCellLocation of PhoneInterfaceManager.java, there is a possible permission bypass due to a missing SDK version check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-15877MedApr 28, 2020
    risk 0.36cvss 5.5epss 0.00

    In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's…

  • CVE-2019-15876MedApr 28, 2020
    risk 0.36cvss 5.5epss 0.00

    In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing…

  • CVE-2020-0035MedMar 10, 2020
    risk 0.36cvss 5.5epss 0.00

    In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2020-0023MedFeb 13, 2020
    risk 0.36cvss 5.5epss 0.00

    In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User…

  • CVE-2019-2229MedDec 6, 2019
    risk 0.36cvss 5.5epss 0.00

    In updateWidget of BaseWidgetProvider.java, there is a possible leak of user data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…

  • CVE-2019-15386MedNov 14, 2019
    risk 0.36cvss 5.5epss 0.00

    The Lava Z60s Android device with a build fingerprint of LAVA/Z60s/Z60s:8.1.0/O11019/1530331229:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to…

  • CVE-2019-2110MedOct 11, 2019
    risk 0.36cvss 5.5epss 0.00

    In ScreenRotationAnimation of ScreenRotationAnimation.java, there is a possible capture of a secure screen due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2019-13013MedAug 23, 2019
    risk 0.36cvss 5.5epss 0.00

    Little Snitch versions 4.3.0 to 4.3.2 have a local privilege escalation vulnerability in their privileged helper tool. The privileged helper tool implements an XPC interface which is available to any process and allows directory listings and copying files as root.

  • CVE-2019-2137MedAug 20, 2019
    risk 0.36cvss 5.5epss 0.00

    In the endCall() function of TelecomManager.java, there is a possible Denial of Service due to a missing permission check. This could lead to local denial of access to Emergency Services with User execution privileges needed. User interaction is not needed for exploitation.…

  • CVE-2019-2117MedJul 8, 2019
    risk 0.36cvss 5.5epss 0.00

    In checkQueryPermission of TelephonyProvider.java, there is a possible disclosure of secure data due to a missing permission check. This could lead to local information disclosure about carrier systems with no additional execution privileges needed. User interaction is not…

  • CVE-2018-14997MedApr 25, 2019
    risk 0.36cvss 5.5epss 0.00

    The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains the android framework (i.e., system_server) with a package name of android that has been modified by Leagoo or another entity in the…

  • CVE-2019-3835MedMar 25, 2019
    risk 0.36cvss 5.5epss 0.03

    It was found that the superexec operator was available in the internal dictionary in ghostscript before 9.27. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER.

  • CVE-2018-9548MedDec 6, 2018
    risk 0.36cvss 5.5epss 0.00

    In multiple functions of ContentProvider.java, there is a possible permission bypass due to a missing URI validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product:…

  • CVE-2018-9457MedNov 14, 2018
    risk 0.36cvss 5.5epss 0.00

    In onCheckedChanged of BluetoothPairingController.java, there is a possible way to retrieve contact information due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2017-6693MedJun 13, 2017
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local attacker to access information stored in the file system of an affected system, aka Unauthorized Directory Access. More Information: CSCvd76286. Known Affected…

  • CVE-2026-82273MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when mapUserToResourceId callback is omitted from configuration. Authenticated attackers can enumerate all threads via GET /api/memory/threads and read…

  • CVE-2026-55545MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket,…

  • CVE-2026-54746MedAug 28, 2026
    risk 0.35cvss 6.4epss 0.00

    Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not verify that a request's worker ID belongs to the tenant identified by the bearer-token context in…

  • CVE-2026-81759MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Contributor Broken Access Control in WpEvently <= 5.5.0 versions.