CWE-862
Missing Authorization
Description
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-665
CVEs mapped to this weakness (9,268)
page 57 of 464| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-35665 | Hig | 0.51 | 7.8 | 0.00 | Sep 11, 2023 | In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2023-38464 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38460 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38459 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38458 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38456 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38455 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38453 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38452 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38451 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38450 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38449 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38444 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-38443 | Hig | 0.51 | 7.8 | 0.00 | Sep 4, 2023 | In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges | ||
| CVE-2023-24674 | Hig | 0.51 | 7.8 | 0.00 | Sep 1, 2023 | Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter. | ||
| CVE-2023-21257 | Hig | 0.51 | 7.8 | 0.00 | Jul 13, 2023 | In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2023-21248 | Hig | 0.51 | 7.8 | 0.00 | Jul 13, 2023 | In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2023-21247 | Hig | 0.51 | 7.8 | 0.00 | Jul 13, 2023 | In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.… | ||
| CVE-2023-30929 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | ||
| CVE-2023-30928 | Hig | 0.51 | 7.8 | 0.00 | Jul 12, 2023 | In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. |
- risk 0.51cvss 7.8epss 0.00
In multiple files, there is a possible way to import a contact from another user due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
In vowifiservice, there is a possible missing permission check.This could lead to local escalation of privilege with no additional execution privileges
- risk 0.51cvss 7.8epss 0.00
Permissions vulnerability found in Bludit CMS v.4.0.0 allows local attackers to escalate privileges via the role:admin parameter.
- risk 0.51cvss 7.8epss 0.00
In updateSettingsInternalLI of InstallPackageHelper.java, there is a possible way to sideload an app in the work profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.51cvss 7.8epss 0.00
In getAvailabilityStatus of WifiScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.51cvss 7.8epss 0.00
In getAvailabilityStatus of BluetoothScanningMainSwitchPreferenceController.java, there is a possible way to bypass a device policy restriction due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed.…
- risk 0.51cvss 7.8epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
- risk 0.51cvss 7.8epss 0.00
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.