VYPR

CWE-862

Missing Authorization

ClassIncompleteLikelihood: High

Description

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-665

CVEs mapped to this weakness (9,259)

page 463 of 463
  • CVE-2019-17055LowOct 1, 2019
    risk 0.00cvss 3.3epss 0.01

    base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.

  • CVE-2019-15030MedSep 13, 2019
    risk 0.00cvss 4.4epss 0.00

    In the Linux kernel through 5.2.14 on the powerpc platform, a local user can read vector registers of other users' processes via a Facility Unavailable exception. To exploit the venerability, a local user starts a transaction (via the hardware transactional memory instruction…

  • CVE-2019-1010246HigJul 18, 2019
    risk 0.00cvss 7.5epss 0.01

    MailCleaner before c888fbb6aaa7c5f8400f637bcf1cbb844de46cd9 is affected by: Unauthenticated MySQL database password information disclosure. The impact is: MySQL database content disclosure (e.g. username, password). The component is: The API call in the function allowAction() in…

  • CVE-2019-9002CriFeb 22, 2019
    risk 0.00cvss 9.8epss 0.02

    An issue was discovered in Tiny Issue 1.3.1 and pixeline Bugs through 1.3.2c. install/config-setup.php allows remote attackers to execute arbitrary PHP code via the database_host parameter if the installer remains present in its original directory after installation is completed.

  • CVE-2019-1000017MedFeb 4, 2019
    risk 0.00cvss 6.5epss 0.01

    Chamilo Chamilo-lms version 1.11.8 and earlier contains an Incorrect Access Control vulnerability in Tickets component that can result in an authenticated user can read all tickets available on the platform, due to lack of access controls. This attack appears to be exploitable…

  • CVE-2018-1116MedJul 10, 2018
    risk 0.00cvss 4.4epss 0.01

    A flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization function in polkitd allows to test for authentication and trigger authentication of unrelated processes owned by other users. This may result in a…

  • CVE-2018-7689HigJun 7, 2018
    risk 0.00cvss 7.1epss 0.01

    Lack of permission checks in the InitializeDevelPackage function in openSUSE Open Build Service before 2.9.3 allowed authenticated users to modify packages where they do not have write permissions.

  • CVE-2018-7688HigJun 7, 2018
    risk 0.00cvss 7.1epss 0.01

    A missing permission check in the review handling of openSUSE Open Build Service before 2.9.3 allowed all authenticated users to modify sources in projects where they do not have write permissions.

  • CVE-2014-6292Oct 3, 2014
    risk 0.00cvss epss 0.01

    The femanager extension before 1.0.9 for TYPO3 allows remote frontend users to modify or delete the records of other frontend users via unspecified vectors.

  • CVE-2014-0167Apr 15, 2014
    risk 0.00cvss epss 0.02

    The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using…

  • CVE-2012-4245Aug 31, 2012
    risk 0.00cvss epss 0.05

    The scriptfu network server in GIMP 2.6 does not require authentication, which allows remote attackers to execute arbitrary commands via the python-fu-eval command.

  • CVE-2010-4408Dec 6, 2010
    risk 0.00cvss epss 0.02

    Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a…

  • CVE-2010-1617Apr 29, 2010
    risk 0.00cvss epss 0.02

    user/view.php in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 does not properly check a role, which allows remote authenticated users to obtain the full names of other users via the course profile page.

  • CVE-2009-3781Oct 26, 2009
    risk 0.00cvss epss 0.02

    The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors.

  • CVE-2009-2282Jul 1, 2009
    risk 0.00cvss epss 0.00

    The Virtual Network Terminal Server daemon (vntsd) for Logical Domains (aka LDoms) in Sun Solaris 10, and OpenSolaris snv_41 through snv_108, on SPARC platforms does not check authorization for guest console access, which allows local control-domain users to gain guest-domain…

  • CVE-2008-6548Mar 30, 2009
    risk 0.00cvss epss 0.01

    The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

  • CVE-2006-4483Aug 31, 2006
    risk 0.00cvss epss 0.03

    The cURL extension files (1) ext/curl/interface.c and (2) ext/curl/streams.c in PHP before 5.1.5 permit the CURLOPT_FOLLOWLOCATION option when open_basedir or safe_mode is enabled, which allows attackers to perform unauthorized actions, possibly related to the realpath cache.

  • CVE-2006-3935Jul 31, 2006
    risk 0.00cvss epss 0.02

    system/workplace/views/admin/admin-main.jsp in Alkacon OpenCms before 6.2.2 does not restrict access to administrator functions, which allows remote authenticated users to (1) send broadcast messages to all users (/workplace/broadcast), (2) list all users (/accounts/users), (3)…

  • CVE-2005-3623Dec 31, 2005
    risk 0.00cvss epss 0.03

    nfs2acl.c in the Linux kernel 2.6.14.4 does not check for MAY_SATTR privilege before setting access controls (ACL) on files on exported NFS filesystems, which allows remote attackers to bypass ACLs for readonly mounted NFS filesystems.